AI-Found Vulnerabilities More Likely to Enable RCE, Google Says
GTIG finds 50% of likely AI-discovered vulnerabilities enable RCE versus 26% of others, as exploitation accelerates; BeyondTrust CVE-2026-1731 was exploited within four days.
Google Threat Intelligence reports 50% of likely AI-discovered vulnerabilities resulted in RCE versus 26% of other CVEs, and medium-risk flaws made up 58% of AI-found bugs. Disclosures doubled to 10,740 in August 2026 while exploited vulnerabilities averaged 18 per month, up from 10.5 in 2025, with zero-day counts jumping to 22 in August. GTIG cites CVE-2026-1731, an unauthenticated command injection flaw in BeyondTrust Privileged Remote Access and Remote Support found autonomously by Hacktron AI, exploited by one cluster within four days of disclosure. It also tracked over 1,500 AI-related vulnerabilities in 2026 (782 in agent orchestration frameworks) and noted Citrix's fixes for two exploited NetScaler zero-days.
- 50% of likely AI-discovered vulnerabilities enabled RCE versus 26% of others.
- Exploited vulnerabilities rose from 10.5 to 18 monthly; zero-days hit 22 in August.
- BeyondTrust CVE-2026-1731, found autonomously by Hacktron AI, was exploited within four days.
- Over 1,500 AI-related CVEs in 2026; 782 hit agent orchestration frameworks.
- Edge and security appliances were 14% of exploited vulnerabilities, mostly high or critical risk.
Vulnerabilities mentionedAll →
- CVE-2026-17319.991%Pre-Authentication OS Command Injection RCE in BeyondTrust Remote Support and PRApublished · BeyondTrust Remote Support (RS) KEV ransomware PoC
Full article442 words · extracted from infosecurity-magazine.com · click to collapse
Vulnerabilities found with the help of AI are disproportionately likely to enable remote code execution (RCE), as disclosures and exploitation both accelerated in 2026.
In research published September 30, Google Threat Intelligence Group (GTIG) found that 50% of vulnerabilities it identified as likely AI-discovered resulted in RCE, against 26% of other CVEs.
Vulnerability disclosures doubled from 5045 in January 2026 to 10,477 in July, reaching 10,740 in August. Exploited vulnerabilities rose from an average of 10.5 a month in 2025 to 18 a month so far in 2026.
Zero-day exploitation rose only marginally, from eight to 11 a month, although it jumped to 22 in August. GTIG suggested most of the growth came from the rapid weaponization of n-days, possibly aided by AI tools that analyze patches and proof-of-concept code.

Medium-risk flaws accounted for 58% of likely AI-discovered vulnerabilities between January and August 2026, compared with 28% of those not attributed to AI, while low-risk flaws made up 39% and 69%, respectively. The ratings are GTIG's, not CVSS scores.
Google said the distribution likely reflects, in large part, how researchers deploy autonomous agents, pointing them at critical infrastructure rather than running broad scans. It also said public data undercounts AI-discovered vulnerabilities.
The company described confirmed exploitation of AI-discovered flaws as an early indicator rather than an established trend.
It cited CVE-2026-1731, an unauthenticated command injection flaw in BeyondTrust Privileged Remote Access and Remote Support that Hacktron AI discovered autonomously.
One threat cluster exploited it within four days of disclosure, and five more followed within seven days.
Orchestration Tools and Edge Devices Concentrate Risk
GTIG tracked more than 1500 AI-related vulnerabilities disclosed in 2026. Agent orchestration frameworks accounted for 782, while inference and serving infrastructure accounted for 212, nearly a quarter of which involved unauthenticated APIs or server-side request forgery.
Only a handful have been confirmed as exploited, and GTIG has yet to see zero-day exploitation of AI infrastructure.
Exploitation overall remained concentrated at the perimeter: edge and security appliances made up 14% of exploited vulnerabilities in 2026, and over 65% of those edge flaws were rated high or critical risk.
The research follows Citrix's fixes for two exploited NetScaler zero-days, one of which GTIG and Mandiant have tracked in active attacks.
"Given the active exploitation, NetScaler customers should prioritize examining their systems for compromise before upgrading/patching," Charles Carmakal, CTO at Mandiant, wrote on LinkedIn on September 27. "Patching alone may not eradicate the threat actor from your environment."
