HomeRisk ManagementsAI-Discovered Vulnerabilities More Likely to Enable RCE, According to Google

AI-Discovered Vulnerabilities More Likely to Enable RCE, According to Google

Published on

spot_img

Rising Vulnerabilities and AI: A 2026 Analysis

In a recent significant development, the Google Threat Intelligence Group (GTIG) published research that highlights an alarming trend regarding vulnerabilities discovered with the assistance of artificial intelligence (AI). According to the findings, vulnerabilities identified through AI are disproportionately linked to enabling remote code execution (RCE), with both the disclosure and exploitation of these vulnerabilities surging throughout 2026.

Published on September 30, the GTIG research reveals compelling statistics: approximately 50% of vulnerabilities classified as likely AI-discovered resulted in RCE, as opposed to just 26% of other Common Vulnerabilities and Exposures (CVEs). This notable distinction underscores the extraordinary impact of AI technologies in vulnerability detection and the consequential risks they pose to cybersecurity.

The data further reveals a dramatic increase in vulnerability disclosures, doubling from 5,045 in January 2026 to a staggering 10,477 by July. By August, this number climbed even higher, reaching 10,740 disclosures. Alongside this spike in reported vulnerabilities, the rate of exploited vulnerabilities rose substantially. On average, only 10.5 vulnerabilities were exploited each month in 2025; however, this figure increased to 18 per month in 2026. Interestingly, when examining zero-day vulnerabilities—known flaws that have not yet been patched—the increase was marginal, rising from eight to 11 a month, although it saw a more pronounced surge to 22 in August alone.

GTIG suggested that the majority of this growth in exploitation may be attributed to the rapid weaponization of "n-days," or vulnerabilities that are known and have been patched but are still exploitable. AI tools likely facilitate this process by analyzing patches and generating proof-of-concept codes, making it easier for threat actors to launch attacks.

A closer look at the nature of these vulnerabilities reveals that medium-risk flaws comprised 58% of those discovered through AI between January and August of 2026. In contrast, only 28% of vulnerabilities not attributed to AI fell into this category. When considering low-risk vulnerabilities, they represented 39% of AI-discovered issues compared to a staggering 69% for non-AI vulnerabilities. GTIG emphasized that these ratings reflect their assessments and are not based on Common Vulnerability Scoring System (CVSS) scores.

The manner in which researchers deploy autonomous agents likely contributes to this disparity. It appears that many researchers direct their AI tools at critical infrastructure rather than conducting broad scans, which could explain why certain vulnerabilities are more prevalent in the AI-discovered category. GTIG also noted that public data may undercount the true number of AI-discovered vulnerabilities, hinting at an even more profound issue lurking beneath the surface.

Google’s report classifies the confirmed exploitation of AI-discovered vulnerabilities as an early warning signal rather than an established trend. A prime example cited in the research is CVE-2026-1731, an unauthenticated command injection vulnerability found in BeyondTrust’s Privileged Remote Access and Remote Support software. This flaw was autonomously discovered by Hacktron AI, leading to its exploitation by one identified threat cluster within just four days of being disclosed. Following this prompt exploitation, an additional five actors attempted exploitation within a week.

Concentrated Risk Factors: Tools and Devices

As the GTIG continues to track vulnerabilities associated with AI, it has identified over 1,500 vulnerabilities disclosed in 2026. Notably, agent orchestration frameworks were responsible for 782 vulnerabilities, while inference and serving infrastructures accounted for 212—approximately 25% of which involved unauthenticated APIs or server-side request forgery.

Despite the sheer number of vulnerabilities identified, exploitation remains concentrated primarily at network perimeters. Edge and security appliances accounted for 14% of the total exploited vulnerabilities in 2026. Alarmingly, more than 65% of these edge vulnerabilities were rated high or critical risk, indicating a significant threat landscape.

This research follows closely behind Citrix’s disclosure and fixes for two exploited NetScaler zero-days, which GTIG and Mandiant have tracked as part of ongoing active attacks. As Charles Carmakal, Chief Technology Officer at Mandiant, noted in a LinkedIn post on September 27, “Given the active exploitation, NetScaler customers should prioritize examining their systems for compromise before upgrading or patching. Patching alone may not eradicate the threat actor from your environment.”

The findings discussed in the GTIG report serve as a critical reminder of the evolving threat landscape influenced by advancements in AI technologies. As organizations grapple with an increasing flood of vulnerabilities, the imperative to understand and mitigate these risks has never been more urgent. The interplay between AI, vulnerability discovery, and exploitation highlights the need for robust security measures and continual vigilance in defending against potential cyber threats.

Source link

Latest articles

UAE Fends Off Iranian Cyberattacks

Gulf Kingdoms Cite Information Sharing and Private Sector Support in Cyber Defense In a world...

The MFA You Have Isn’t What You Think It Is

The Evolving Landscape of Multi-Factor Authentication: Challenges and Solutions For nearly a decade, organizations have...

CyberASAP Marks 10th Anniversary with Unique Event on the Future of Cyber Security Innovation in the UK

In 2026, the Cyber Security Academic Startup Accelerator Programme, widely known as CyberASAP, proudly...

Unsloth Model Picker Encountered a Code Execution Issue

In recent discussions about the safety and security of artificial intelligence (AI) models, a...

More like this

UAE Fends Off Iranian Cyberattacks

Gulf Kingdoms Cite Information Sharing and Private Sector Support in Cyber Defense In a world...

The MFA You Have Isn’t What You Think It Is

The Evolving Landscape of Multi-Factor Authentication: Challenges and Solutions For nearly a decade, organizations have...

CyberASAP Marks 10th Anniversary with Unique Event on the Future of Cyber Security Innovation in the UK

In 2026, the Cyber Security Academic Startup Accelerator Programme, widely known as CyberASAP, proudly...