AI accelerates n-day attacks, as flaw disclosures and exploits double
Google Threat Intelligence says 141 flaws were exploited by August 2026, exceeding all of 2025, with AI tooling accelerating n-day weaponization and shrinking exploit timelines.
Google's Threat Intelligence Group recorded 141 vulnerabilities exploited in the wild between January and August 2026 versus 127 in all of 2025, while monthly disclosures doubled from 5,045 in January to 10,740 in August. The median time from CVE publication to confirmed exploitation fell from 120 days in 2025 to 80 days in H1 2026, which researchers attribute partly to AI-assisted analysis of patches and PoC code. Edge and security appliances accounted for 14% of exploited flaws (two-thirds high or critical severity), and AI-discovered vulnerabilities skew more severe, with 50% enabling remote code execution versus 26% of conventional disclosures.