AI-Discovered Vulnerabilities Exploitation Accelerates
Five threat clusters exploited a critical remote code execution flaw in BeyondTrust products within a week of its disclosure, a vulnerability found

Five distinct threat clusters weaponized the critical vulnerability CVE-2026-1731 within seven days of its disclosure. This flaw allows unauthenticated attackers to inject operating system commands into BeyondTrust Corp.'s Privileged Remote Access and Remote Support products. The vulnerability was found autonomously by a research agent from Hacktron AI Inc..
Context
Research from the Google Threat Intelligence Group (GTIG) quantifies the heightened danger of AI-discovered flaws. Published on September 30, 2026, the study found that 50% of vulnerabilities identified as likely AI-discovered resulted in remote code execution. In contrast, only 26% of other CVEs led to RCE. GTIG suggested most growth in exploitation now comes from the rapid weaponization of n-days, possibly aided by AI tools that analyze patches and proof-of-concept code.
The group tracked more than 1,500 AI-related vulnerabilities disclosed in 2026. The distribution of these flaws reveals targeted research priorities.
| AI Vulnerability Category | Count in 2026 |
|---|---|
| Agent orchestration frameworks | 782 |
| Inference and serving infrastructure | 212 |
Nearly a quarter of the inference infrastructure vulnerabilities involved unauthenticated APIs or server-side request forgery. GTIG stated that the risk ratings reflect how researchers deploy autonomous agents at critical infrastructure and sensitive privilege boundaries deliberately, rather than running broad scans. This targeting is evident in the risk distribution of AI-discovered bugs compared to conventional finds.
| Risk Tier | AI-Discovered Vulnerabilities | Non-AI Vulnerabilities |
|---|---|---|
| Moderate | 58% | 28% |
| Low | 39% | 69% |
Google described confirmed exploitation of AI-discovered flaws as an early indicator, not an established trend. Only a handful have been confirmed as exploited, and GTIG has yet to see zero-day exploitation of AI infrastructure itself. The public data likely undercounts AI-assisted discoveries because vulnerability databases lack a standard tag for them, and large cloud providers often fix AI-surfaced bugs without requesting CVE identifiers.
Trends
Vulnerability disclosure and exploitation rates have surged dramatically in 2026. Disclosures doubled from 5,045 in January to 10,740 in August. Exploited vulnerabilities in the wild rose from an average of 10.5 per month in 2025 to 18 per month so far this year. Between January and August, attackers exploited 141 newly disclosed flaws, already exceeding the 127 exploited in all of 2025. The current exploitation rate is about one flaw in every 431 disclosures.
Zero-day exploitation has also intensified, averaging 11 per month in 2026 compared to 8 per month in 2025. Most months saw between 8 and 12 zero-day exploits until a spike in August, which recorded 22. Zero-days constituted 62% of the 141 exploited flaws this year. However, researchers note that most growth in exploitation actually came from n-days-flaws exploited after disclosure and patching. The number of exploited high-risk flaws has also jumped, with 75 recorded this year versus 28 in all of 2025.
Related Threats
The accelerated threat landscape extends beyond AI-discovered bugs. The research follows Citrix's fixes for two exploited NetScaler zero-days, one of which GTIG and Mandiant tracked in active attacks. This parallel activity shows a broader environment of rapid weaponization. Charles Carmakal, CTO at Mandiant, emphasized the urgency for defenders managing such incidents.
He stated, "Given the active exploitation, NetScaler customers should prioritize examining their systems for compromise before upgrading/patching." Carmakal added, "Patching alone may not eradicate the threat actor from your environment."
Edge and security appliances remain a key target, making up 14% of exploited vulnerabilities in 2026. Over 65% of these exploited edge flaws were rated high or critical risk. Defenders are urged to prioritize examining systems for compromise before applying upgrades or patches, as active exploitation may persist even after fixes are deployed.





