Fourteen of the 1,061 vulnerabilities attributed to AI-assisted discovery have been confirmed as exploited in the wild — a 1.3% exploitation rate that, VulnCheck’s research shows, “roughly matching the overall exploitation rate of all vulnerabilities for the reported period.”
AI-assisted discovery and the exploitation picture
VulnCheck’s State of Exploitation H1 2026 report, authored by vulnerability researcher Patrick Garrity, finds that vulnerabilities discovered using AI tools are being exploited at essentially the same rate as those discovered without AI. Garrity recorded 1,061 AI-attributed vulnerabilities and confirmed 14 as exploited in the wild, producing the 1.3% figure cited above. He frames these data as a corrective to alarmist scenarios that forecast a rapid, AI-driven “vulnpocalypse.”
Garrity wrote that current vulnerability intelligence shows that the use of frontier AI models is “more likely to give cyber defenders an advantage in strengthening software than to give attackers an advantage in discovering vulnerabilities before the software producers do.” That assessment, voiced in the report, is central to VulnCheck’s interpretation of the early AI-discovery signal.
Anthropic’s Project Glasswing: volume versus impact
The report highlights Anthropic’s Project Glasswing as a case study in scale and sorting. Anthropic reported more than 23,000 findings through Project Glasswing; of those, VulnCheck records 126 that have resulted in published CVEs, and just one that has been confirmed as exploited in the wild. The gulf between raw findings and published CVEs — and between CVEs and confirmed exploitation — is a core element of VulnCheck’s argument that large AI-assisted discovery output has not translated into a proportional explosion of exploited flaws.
KEV counts and faster timelines
VulnCheck identified nearly 500 known exploited vulnerabilities (KEVs) during the first half of 2026. Those KEVs are being exploited faster than in the recent past: the median time from CVE publication to KEV fell from 120 days in 2025 to 80 days in H1 2026. The report also shows that 23.43% of KEVs recorded in H1 2026 had evidence of exploitation on or before the CVE publication date, a modest decline from the 28.93% share of one-day/zero-day KEVs observed in 2025.
Early exploitation activity remained significant in absolute terms: roughly 200 CVEs became exploited within 31 days during the first half of 2026. Yet Garrity notes a notable mismatch between the pace of CVE issuance and the scaling of early exploitation: “Early exploitation activity has not scaled at the same pace as CVE issuance.” That dynamic — faster median exploitation but a smaller share exploited immediately on publication than in the prior year — is a focal tension in the report.
Most-targeted technologies, and AI as a new attack surface
Content management systems (CMS) continued to dominate as the most targeted technology category, accounting for 163 KEVs — roughly one-third of all recorded KEVs in H1 2026. They were followed by network edge devices (68 KEVs), operating systems (44 KEVs) and server software (40 KEVs). Those four categories together account for a large share of exploitation activity recorded in the period.
The report also flags AI products as an emerging attack surface. VulnCheck documents known exploitation affecting model-building tools, workload-scaling platforms, AI gateways, agents and workflow automation. Those categories appear among the new vectors where defenders and adversaries will contest control as AI platforms continue to be integrated into production environments.
What this means for technologists and security teams, policymakers and procurement leaders
- Technologists and security teams: The data suggest AI-assisted discovery has so far yielded more findings than exploitable, published CVEs; teams should continue to prioritize remediation in high-risk categories named in the report (CMS, network edge, OS, server software), while adding attention to AI-build and orchestration components now showing exploitation.
- Policymakers and regulators: Faster median times from CVE publication to KEV underline the value of timely disclosure and coordinated mitigation — the report’s numbers give urgency to processes that move fixes and mitigations from vendors to users within measured windows.
- Affected enterprises and procurement leaders: Anthropic’s Project Glasswing example — 23,000 findings, 126 CVEs, one confirmed exploited — indicates that vendor-reported discovery volumes do not translate directly into exploit risk; procurement and risk teams should evaluate vendor discovery programs by how many findings become actionable CVEs and how quickly mitigations are deployed.
VulnCheck’s H1 2026 snapshot complicates a simple narrative of AI as an accelerant of exploitation. The headline numbers — 1.3% of AI-attributed vulnerabilities confirmed exploited, nearly 500 KEVs identified, a falling median time to exploitation — together suggest a shifting balance: defenders may be harvesting AI to find and fix flaws, even as exploitation timelines compress. The pressing question the report leaves on the table is whether that balance will hold as raw AI discovery volumes grow and as AI components themselves become increasingly targeted.




