Google Threat Intelligence Group says software vulnerability disclosures accelerated sharply in 2026, with monthly totals roughly doubling between January and August, while the number of flaws seen exploited in the wild also increased. In its analysis of disclosures from January 2025 through August 2026, GTIG said monthly disclosures rose from 5,045 in January 2026 to 10,740 in August, and it recorded 141 distinct exploited vulnerabilities in the first eight months of 2026, more than the 127 it saw in all of 2025 (SecurityWeek).
GTIG argued that AI is affecting more than the pace of discovery. The group said vulnerabilities it identified as likely discovered by AI showed a noticeably different profile from non-AI findings. Half of the AI-discovered vulnerabilities in the report resulted in remote code execution, compared with 26% of non-AI vulnerabilities, which GTIG said may reflect AI models’ ability to uncover memory-corruption and logic bugs that traditional static analyzers can miss (SecurityWeek).
The report also said likely AI-discovered vulnerabilities were less concentrated in the low-risk tier and more concentrated in the medium-risk tier than other disclosures. GTIG found that 39% of likely AI-discovered vulnerabilities were rated low-risk and 58% medium-risk, versus 69% and 28% respectively for non-AI vulnerabilities. It attributed that gap in part to how security teams are deploying AI agents, with a focus on critical infrastructure and sensitive privilege boundaries where higher-impact issues are more likely to surface (SecurityWeek).
Exploitation is rising too
Even with the jump in disclosures, GTIG said exploitation increased as well. Beyond the 141 distinct exploited vulnerabilities recorded through August, the report said zero-day exploitation averaged 11 per month in 2026, up from eight per month in 2025, though GTIG described that increase as marginal overall despite a spike to 22 in August (SecurityWeek).
GTIG said it has already confirmed in-the-wild exploitation of at least one AI-discovered vulnerability, while cautioning that it sees this as an early signal rather than a settled trend. The example it cited was CVE-2026-1731, an unauthenticated OS command injection flaw in BeyondTrust Privileged Remote Access and Remote Support that SecurityWeek reported was discovered autonomously by the Hacktron AI research agent. One threat cluster exploited the flaw within four days of public disclosure, and five more followed within a week ().