Attackers have already exploited more security vulnerabilities in 2026 than they did in all of 2025, with artificial intelligence tools accelerating how quickly they weaponize publicly disclosed flaws. Google's Threat Intelligence Group documented 141 vulnerabilities exploited in the wild between January and August 2026, compared to 127 for the entire previous year, as monthly vulnerability disclosures doubled from 5,045 in January to 10,740 in August. The research suggests threat actors are increasingly turning AI models toward already-known flaws—called n-days—rather than hunting for undiscovered zero-day vulnerabilities.
The monthly rate at which vulnerabilities are exploited climbed from 10.5 per month in 2025 to nearly 18 in 2026, far outpacing the growth in zero-day exploits, which rose only slightly from 8 per month last year to 11 this year. High-risk flaw exploits more than doubled, jumping from 28 in 2025 to 75 in the first eight months of 2026, mirroring a spike in high-risk vulnerability disclosures that grew from 131 in January to 350 in August. The proportion of disclosed flaws that are actually exploited remains tiny at 0.23%—roughly 1 in 431—but the median time from a CVE's publication to confirmed exploitation dropped from 120 days in 2025 to 80 days in the first half of 2026. Edge and security appliances accounted for 14% of exploited vulnerabilities from January to August, with two-thirds of those flaws rated high or critical severity, while enterprise directory and collaboration hubs represented another 11%.
The GTIG researchers note that threat actors may find it "more accessible or efficient to use LLMs and AI tools to automate analysis of differences between product versions, patches, vulnerability disclosure announcements, and Proof-of-Concept code to rapidly weaponize n-days, rather than to discover new zero-days." Among AI-discovered vulnerabilities, over half were medium severity and above, compared to under a third across all disclosed vulnerabilities, and 50% of AI-discovered flaws include remote code execution as an impact versus 26% across conventional disclosures. The report documents a North Korean state-linked group that sent thousands of prompts to Gemini to analyze known vulnerabilities and validate proof-of-concept exploits, while a command injection flaw in BeyondTrust Privileged Remote Access was weaponized within four days of public disclosure and exploited by six threat clusters within a week.
The report warns that automatic CVE assignment policies across open-source ecosystems might inflate disclosure numbers, noting that vulnerabilities mentioning the Linux kernel alone produced roughly 5,000 CVEs between January and August with no zero-days exploited in the wild. Attackers continue targeting network-edge appliances and unauthenticated public management interfaces because they reach systems that enterprise endpoint detection and response agents can't see, the researchers said, adding that "adversary exploitation activity remains concentrated in perimeter appliances and exposed enterprise services." As both vulnerability discovery and exploitation are expected to grow in the medium term, companies must shift from patching vulnerabilities en masse to triaging them using threat intelligence and deploying automatic agentic remediation, the report concludes. With CVE volume projected to approach 96,000 by year-end, security teams need to know whether a vulnerability has a working exploit, whether attackers are using it, whether it touches their exposed assets, and whether there's a fix—context that turns vulnerability data into a prioritization decision. Organizations that continue treating all disclosed flaws as equally urgent will find their patch cycles overwhelmed long before adversaries run out of targets. Defenders who can't match the speed of AI-assisted exploit development may discover that traditional triage workflows have become a competitive disadvantage in an arms race increasingly shaped by automation.

