AIToday
THE DECODERPublished: Aug 2, 2026, 22:01 JST4 min read

AI finds security flaws, but 1.3% actually exploited

AI finds security flaws, but 1.3% actually exploited

Key takeaway

  • AI systems are discovering thousands of security vulnerabilities, but almost none of them get exploited in real-world attacks.

  • In the first half of 2026, AI-assisted discovery found 1,061 flaws with only 14 confirmed exploitations — a 1.3% rate no different from traditional vulnerability discovery.

  • The real concern for defenders is not the volume of findings but the acceleration of exploitation timelines: vulnerabilities are now exploited within 80 days of disclosure on average, down from 120 days a year earlier.

3 Key Points

  1. What happened

    VulnCheck found that in the first half of 2026, AI-assisted discovery uncovered 1,061 vulnerabilities, but only 14 showed confirmed exploitation — a 1.3% rate matching the overall vulnerability exploitation rate. Anthropic's Project Glasswing produced more than 23,000 findings, leading to 126 published entries and a single confirmed attack.

  2. Why it matters

    The volume of AI-generated security findings creates noise for defenders. While AI can surface flaws at scale, the sheer number tells security teams very little about which ones pose actual risk — they still face the burden of determining which findings warrant attention and resources.

  3. What to watch

    Exploitation speed is accelerating. Half of all flaws now see their first confirmed attack within 80 days of disclosure, down from 120 days the year before, with about 23 percent exploited on or before the day of disclosure. Content management systems remain the top target, accounting for a third of all cases, and AI products themselves (including model-building tools and agent interfaces) are a growing attack surface.

In Depth

Read the full story

In the first half of 2026, security research firm VulnCheck conducted a comprehensive analysis of how often vulnerabilities discovered with AI assistance actually end up being exploited in the wild. The findings present a nuanced picture: while AI tools are surfacing security flaws at scale, the overwhelming majority never see real-world attack.

VulnCheck's Patrick Garrity counted 1,061 vulnerabilities traced to AI-assisted discovery during this period, of which only 14 showed confirmed exploitation — representing a 1.3% exploitation rate. This rate is roughly equivalent to vulnerabilities discovered through traditional means, suggesting that AI discovery does not systematically produce higher-risk findings. Anthropic's Project Glasswing, a dedicated effort to surface security issues, illustrates the scale disparity even more starkly: it generated more than 23,000 findings, which ultimately led to 126 published entries in vulnerability databases and a single confirmed attack.

Despite the low overall exploitation rate, the timeline for attacks has compressed significantly. Half of all disclosed flaws now experience their first confirmed exploitation within 80 days, a substantial improvement from the 120-day median a year earlier. The acceleration is even sharper for rapid attacks: approximately 23 percent of vulnerabilities were exploited on or before the day of disclosure, indicating that defenders face a critical window immediately after public knowledge of a flaw emerges. About 200 vulnerabilities were attacked within a month, even as the total number of reported vulnerabilities continues to climb.

Geographically and by target type, attackers show clear preferences. Website content management systems account for a third of all exploitation cases, making them the most-targeted category. Additionally, AI products themselves — including model-building tools and agent interfaces — have emerged as a growing attack surface, reflecting the expanding footprint of AI infrastructure that defenders must now protect. Garrity emphasizes that the sheer volume of findings from AI, while impressive in absolute terms, actually obscures the true risk landscape: defenders cannot meaningfully prioritize between thousands of flagged issues without understanding which ones attackers are likely to target.

Context & Analysis

The rapid scaling of AI-assisted vulnerability discovery has created a paradox for security teams: more findings do not equal more risk. VulnCheck's analysis shows that AI is generating vulnerabilities at an unprecedented scale — Anthropic's Project Glasswing alone produced more than 23,000 findings — yet the exploitation rate (1.3%) remains flat compared to traditional discovery methods. This disconnect reveals that volume alone is not a useful signal for defenders deciding where to focus remediation efforts.

What has shifted, however, is the speed of exploitation. The median time from disclosure to first confirmed attack has dropped sharply from 120 days to 80 days, and nearly a quarter of vulnerabilities are now under attack within hours or on the same day as disclosure. This acceleration suggests that while AI-generated findings as a whole pose no greater risk than traditional ones, the defenders who do not respond quickly to any disclosed flaw face an increasingly compressed window. The growing prominence of AI products themselves — model-building tools, agent interfaces — as an attack surface compounds the challenge, as security teams must now defend novel infrastructure alongside traditional targets like content management systems.

FAQ

How many AI-discovered vulnerabilities actually get exploited?
In the first half of 2026, VulnCheck counted 1,061 vulnerabilities traced to AI-assisted discovery, with only 14 showing confirmed exploitation — a 1.3% rate. Anthropic's Project Glasswing produced more than 23,000 findings, which led to 126 published entries and a single confirmed attack.
How fast are attackers exploiting vulnerabilities after disclosure?
Half of all flaws now see their first confirmed exploitation within 80 days of disclosure, down from 120 days the year before. About 23 percent were exploited on or before the day of disclosure.
What systems are most vulnerable to attack?
Website content management systems take the most hits, accounting for a third of all cases. AI products themselves, including model-building tools and agent interfaces, are flagged as a growing attack surface.

Get AI news like this every morning

AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.

Free · takes 30 seconds · unsubscribe anytime

Ask AI

Ask AI anything about this article. Q&As are published on this page for other readers too.

Next articleGoogle DeepMind unveils Gemini Robotics 2 with full-body control

The AI news that matters, in one minute each morning.

Sign up free