Skip to main content
CybersecurityVulnerability Management

AI-Assisted Tools Discover More Vulnerabilities, But Exploitation Rate Remains Steady

Researcher working at a lab bench with technology and security tools, surrounded by notes and diagrams.

“While AI-assisted vulnerability discovery clearly has value for both attackers and defenders, the data does not suggest that AI discovered vulnerabilities are inherently more likely to be exploited than those found through traditional methods,” Patrick Garrity wrote — a finding grounded in hard counts: 1,061 AI-attributed vulnerabilities discovered in the first six months of 2026, and 14 of those (1.3%) were observed exploited in the wild.

VulnCheck’s tally: AI finds more bugs, but exploitation rates hold steady

VulnCheck published a mid‑year review showing that AI-assisted systems such as Anthropic’s Project Glasswing, Microsoft’s MDASH and OpenAI’s Daybreak are contributing to the growing pool of disclosed defects. Garrity, a security researcher at VulnCheck and the report’s author, attributed 1,061 vulnerabilities to AI-assisted discovery during the first half of 2026. Of those, 14 were exploited — a 1.3% exploitation rate that VulnCheck says aligns with the exploitation rate for all vulnerabilities disclosed in the same period.

The report frames AI tools as amplifiers of discovery for both attackers and defenders, but the empirical record through June 2026 does not show AI-discovered flaws being exploited more often than traditionally discovered ones.

Timing matters: models launched mid‑year and exploitation is getting faster

VulnCheck cautioned that the dataset covers only the first half of 2026 and that the largest vulnerability-hunting models were not active for that whole span. Project Glasswing rolled out in April, while Microsoft’s MDASH and OpenAI’s Daybreak were unveiled in May. That staggered availability limits how representative early figures may be for the remainder of the year.

Separately, exploitation is accelerating. VulnCheck found that the average time from CVE publication to observed exploitation decreased from 120 days in 2025 to 80 days in the first half of 2026. That compression of time-to-exploitation increases the pressure on defenders to triage and patch quickly as disclosures proliferate.

Which technology categories are being attacked most

VulnCheck identified 495 known exploited vulnerabilities in the first half of 2026 and analyzed how those break down by product category. Content management systems accounted for nearly one-third of the exploited items. Network edge devices were responsible for almost 14%, operating systems for nearly 9%, server software for 8%, and AI products — identified as an emerging attack surface — for almost 6%.

Those concentrations point to predictable high-value targets but also highlight AI products joining the list of actively exploited categories.

What this means for technologists, policymakers, and affected enterprises

  • Technologists and security teams: The accelerated time to exploitation and a rising volume of disclosures — particularly as major AI discovery models ramp up — mean teams will be pressured to triage and patch faster. The July Patch Tuesday spike at Microsoft (622 vulnerabilities) illustrates how quickly vulnerability workloads can swell.
  • Policymakers and regulators: The arrival and rapid rollout of AI-assisted discovery tools complicates the timeline for assessing systemic risk; though AI-discovered vulnerabilities were not exploited at higher rates in H1 2026, the mid‑year launches of Project Glasswing, MDASH and Daybreak mean oversight and notification practices may need to account for expanding discovery capacity.
  • Affected enterprises and procurement leaders: The categories most exploited — content management systems, network edge devices, operating systems and server software — remain priorities for inventory, patching and risk assessment. Organizations should track how AI tools change disclosure volume; Microsoft’s June-to‑July jump (206 to 622 vulnerabilities) provides a concrete example of changing patch workloads.

Conclusion

VulnCheck’s mid‑year snapshot offers a clear, if narrowly scoped, answer: AI-assisted discovery has increased the number of reported vulnerabilities, but through the first half of 2026 those AI‑found bugs were no more likely to be observed exploited than other disclosures. The accelerating speed from publication to exploitation — and the fact that the most prominent AI discovery models only came online partway through the period — leave open a practical question that the data cannot yet resolve: as AI tools run longer and generate larger volumes of findings, will absolute exploitation counts rise even if per‑vulnerability rates remain steady? The July Patch Tuesday surge and the identification of AI products as an emerging attack surface mean defenders and decision‑makers will be watching that trend closely.

Original report: https://cyberscoop.com/ai-assisted-security-tools-are-finding-more-bugs-but-the-threat-level-has-not-changed/