Monthly CVE Disclosures Double as AI Speeds Exploitation
Google says monthly CVE disclosures doubled to 10,740 by August 2026, exploited flaws nearly doubled, and AI-found bugs skew toward RCE.
Google Threat Intelligence Group's analysis of vulnerabilities disclosed from January 2025 through August 2026 found monthly CVE disclosures doubling from 5,045 in January 2026 to 10,740 in August, with July and August both above 10,000 and High-Risk disclosures up 167% to about 350 per month, driven by vendors such as TOTOLINK, Oracle's quarterly CPUs, and Linux kernel advisories. Exploited vulnerabilities averaged 18 per month in 2026 versus 10.5 in 2025 — 141 distinct exploited CVEs in the first eight months versus 127 in all of 2025 — though only 0.23% of 2026 disclosures were observed exploited; GTIG attributes the rise mainly to rapid weaponization of patched n-days rather than new zero-days, while average monthly zero-days rose from 8 to 11 and Infosecurity Magazine puts the August count at 22. GTIG estimates 50% of likely AI-discovered vulnerabilities enable remote code execution versus 26% of other CVEs, with medium-risk flaws making up 58% of AI-found bugs. Sources disagree on AI-related totals: Infosecurity Magazine cites over 1,500 in 2026 (782 in agent orchestration frameworks), while SecurityWeek cites 2,076 with roughly half affecting orchestration frameworks; both indicate only a handful, including LiteLLM and Langflow flaws, were confirmed exploited. CVE-2026-1731, an unauthenticated OS command injection flaw in BeyondTrust Privileged Remote Access and Remote Support found autonomously by the Hacktron AI agent, was exploited by one cluster within four days and by five more within seven days, with privilege escalation, data exfiltration, and payloads including SNOWLIGHT, SPARKRAT, and cryptominers. Edge and security appliances accounted for 14% of exploited vulnerabilities from January through August, mostly high or critical risk; Citrix issued fixes for two exploited NetScaler zero-days, and GTIG recommends threat-intelligence-driven triage and agentic remediation over unprioritized mass patching.
- Monthly CVE disclosures doubled from 5,045 in January 2026 to 10,740 in August, with July and August both above 10,000.
- High-Risk disclosures rose 167% to about 350 per month, with spikes tied to TOTOLINK, Oracle quarterly CPUs, and Linux kernel advisories.
- Exploited vulnerabilities averaged 18 per month in 2026 versus 10.5 in 2025 (141 in eight months versus 127 in all of 2025); only 0.23% of 2026 disclosures were observed exploited.
- Average monthly zero-days rose from 8 to 11; Infosecurity Magazine reports the August zero-day count hit 22. GTIG attributes the exploitation rise mainly to rapid n-day weaponization.
- 50% of likely AI-discovered vulnerabilities enable RCE versus 26% of others; medium-risk flaws were 58% of AI-found bugs.
- Sources disagree on 2026 AI-related CVE totals: over 1,500 (782 in agent orchestration frameworks) versus 2,076 (roughly half in orchestration); only a handful, including LiteLLM and Langflow, were confirmed exploited.
- CVE-2026-1731, a BeyondTrust unauthenticated OS command injection flaw found by the Hacktron AI agent, was exploited by one cluster within four days and five more within seven days, including SNOWLIGHT, SPARKRAT, and cryptominer payloads.
- Edge and security appliances were 14% of exploited vulnerabilities, mostly high or critical; Citrix fixed two exploited NetScaler zero-days. GTIG urges intelligence-driven triage over mass patching.
Coverage timelineoldest first · each row is one article
- · 14h agoAI-Found Vulnerabilities More Likely to Enable RCE, Google Says
Infosecurity Magazine· 58
GTIG finds 50% of likely AI-discovered vulnerabilities enable RCE versus 26% of others, as exploitation accelerates; BeyondTrust CVE-2026-1731 was exploited within four days.
- · 14h agoVulnerability Discovery and Exploitation Trends in the AI Era
Google Threat Intelligence· 62
Google Threat Intelligence reports monthly CVE disclosures doubled to 10,740 by August 2026, exploited vulnerabilities rose to 18 monthly, and AI-assisted finds skew toward RCE.
- · 14h ago
Vulnerabilities in this storyAll →
- CVE-2026-17319.991%Pre-Authentication OS Command Injection RCE in BeyondTrust Remote Support and PRApublished · BeyondTrust Remote Support (RS) KEV ransomware PoC