
AI systems are discovering thousands of security vulnerabilities, but almost none of them get exploited in real-world attacks.
In the first half of 2026, AI-assisted discovery found 1,061 flaws with only 14 confirmed exploitations — a 1.3% rate no different from traditional vulnerability discovery.
The real concern for defenders is not the volume of findings but the acceleration of exploitation timelines: vulnerabilities are now exploited within 80 days of disclosure on average, down from 120 days a year earlier.
What happened
VulnCheck found that in the first half of 2026, AI-assisted discovery uncovered 1,061 vulnerabilities, but only 14 showed confirmed exploitation — a 1.3% rate matching the overall vulnerability exploitation rate. Anthropic's Project Glasswing produced more than 23,000 findings, leading to 126 published entries and a single confirmed attack.
Why it matters
The volume of AI-generated security findings creates noise for defenders. While AI can surface flaws at scale, the sheer number tells security teams very little about which ones pose actual risk — they still face the burden of determining which findings warrant attention and resources.
What to watch
Exploitation speed is accelerating. Half of all flaws now see their first confirmed attack within 80 days of disclosure, down from 120 days the year before, with about 23 percent exploited on or before the day of disclosure. Content management systems remain the top target, accounting for a third of all cases, and AI products themselves (including model-building tools and agent interfaces) are a growing attack surface.
In the first half of 2026, security research firm VulnCheck conducted a comprehensive analysis of how often vulnerabilities discovered with AI assistance actually end up being exploited in the wild. The findings present a nuanced picture: while AI tools are surfacing security flaws at scale, the overwhelming majority never see real-world attack.
VulnCheck's Patrick Garrity counted 1,061 vulnerabilities traced to AI-assisted discovery during this period, of which only 14 showed confirmed exploitation — representing a 1.3% exploitation rate. This rate is roughly equivalent to vulnerabilities discovered through traditional means, suggesting that AI discovery does not systematically produce higher-risk findings. Anthropic's Project Glasswing, a dedicated effort to surface security issues, illustrates the scale disparity even more starkly: it generated more than 23,000 findings, which ultimately led to 126 published entries in vulnerability databases and a single confirmed attack.
Despite the low overall exploitation rate, the timeline for attacks has compressed significantly. Half of all disclosed flaws now experience their first confirmed exploitation within 80 days, a substantial improvement from the 120-day median a year earlier. The acceleration is even sharper for rapid attacks: approximately 23 percent of vulnerabilities were exploited on or before the day of disclosure, indicating that defenders face a critical window immediately after public knowledge of a flaw emerges. About 200 vulnerabilities were attacked within a month, even as the total number of reported vulnerabilities continues to climb.
Geographically and by target type, attackers show clear preferences. Website content management systems account for a third of all exploitation cases, making them the most-targeted category. Additionally, AI products themselves — including model-building tools and agent interfaces — have emerged as a growing attack surface, reflecting the expanding footprint of AI infrastructure that defenders must now protect. Garrity emphasizes that the sheer volume of findings from AI, while impressive in absolute terms, actually obscures the true risk landscape: defenders cannot meaningfully prioritize between thousands of flagged issues without understanding which ones attackers are likely to target.
The rapid scaling of AI-assisted vulnerability discovery has created a paradox for security teams: more findings do not equal more risk. VulnCheck's analysis shows that AI is generating vulnerabilities at an unprecedented scale — Anthropic's Project Glasswing alone produced more than 23,000 findings — yet the exploitation rate (1.3%) remains flat compared to traditional discovery methods. This disconnect reveals that volume alone is not a useful signal for defenders deciding where to focus remediation efforts.
What has shifted, however, is the speed of exploitation. The median time from disclosure to first confirmed attack has dropped sharply from 120 days to 80 days, and nearly a quarter of vulnerabilities are now under attack within hours or on the same day as disclosure. This acceleration suggests that while AI-generated findings as a whole pose no greater risk than traditional ones, the defenders who do not respond quickly to any disclosed flaw face an increasingly compressed window. The growing prominence of AI products themselves — model-building tools, agent interfaces — as an attack surface compounds the challenge, as security teams must now defend novel infrastructure alongside traditional targets like content management systems.
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytime
Ask AI anything about this article. Q&As are published on this page for other readers too.
The AI news that matters, in one minute each morning.
Sign up free