Skip to main content
CybersecurityVulnerability Management

AI-Discovered Vulnerabilities Skew Toward Remote Code Execution

Technicians inspect rows of equipment racks and servers in a brightly-lit server room.

"Given the active exploitation, NetScaler customers should prioritize examining their systems for compromise before upgrading/patching," Charles Carmakal, CTO at Mandiant, wrote on LinkedIn on September 27.

Google Threat Intelligence Group's headline: AI-linked flaws more likely to enable RCE

Google Threat Intelligence Group (GTIG) published research on September 30 showing that vulnerabilities GTIG identified as likely discovered with the help of AI were disproportionately likely to enable remote code execution (RCE). GTIG found that 50% of those likely AI-discovered vulnerabilities resulted in RCE, compared with 26% of other CVEs. GTIG described confirmed exploitation of AI-discovered flaws as an early indicator rather than an established trend.

Disclosures and exploitation accelerated through 2026

GTIG's timeline of 2026 shows a sharp rise in disclosures and exploitation. Vulnerability disclosures doubled from 5,045 in January 2026 to 10,477 in July and reached 10,740 in August. Exploited vulnerabilities increased from an average of 10.5 per month in 2025 to 18 per month so far in 2026. Zero-day exploitation rose only marginally overall, from eight per month to 11 per month, but spiked to 22 in August.

GTIG suggested most of the growth in exploitation came from rapid weaponization of n-days — vulnerabilities known to the public — possibly aided by AI tools that analyze patches and proof-of-concept code.

AI discovery skews to medium‑risk flaws and targeted deployments of autonomous agents

GTIG reported a different risk distribution for likely AI-discovered vulnerabilities. Between January and August 2026, medium‑risk flaws accounted for 58% of likely AI-discovered vulnerabilities, compared with 28% of those not attributed to AI. Low‑risk flaws made up 39% of likely AI-discovered cases and 69% of non‑AI cases. GTIG noted the ratings are its own, not CVSS scores, and said the distribution likely reflects how researchers deploy autonomous agents — for example, pointing them at critical infrastructure rather than running broad, indiscriminate scans. GTIG also said publicly available data likely undercounts AI-discovered vulnerabilities.

Agent orchestration frameworks and inference infrastructure concentrate AI-related disclosures

GTIG tracked more than 1,500 AI-related vulnerabilities disclosed in 2026. Agent orchestration frameworks accounted for 782 of those disclosures. Inference and serving infrastructure accounted for 212 disclosures, nearly a quarter of which involved unauthenticated APIs or server-side request forgery (SSRF). GTIG emphasized that, to date, only a handful of those AI infrastructure vulnerabilities have been confirmed as exploited, and it has not yet seen zero‑day exploitation of AI infrastructure itself.

Edge and NetScaler: exploitation remains concentrated at the perimeter

Exploitation in 2026 remained concentrated at the network perimeter. Edge and security appliances made up 14% of exploited vulnerabilities in 2026, and GTIG reported that over 65% of those edge flaws were rated high or critical risk. The research followed Citrix's fixes for two exploited NetScaler zero‑days; GTIG and Mandiant have tracked one of those zero‑days in active attacks. Mandiant's Charles Carmakal warned NetScaler customers to look for compromise before relying solely on patching.

How NetScaler customers, security teams, and procurement leaders should respond

  • NetScaler customers: GTIG and Mandiant tracking of exploited NetScaler zero‑days means customers should prioritize investigating systems for signs of compromise before or alongside patching, as Mandiant advised.
  • Security teams: rapid increases in disclosed vulnerabilities and the higher RCE rate among likely AI‑discovered flaws suggest teams should watch for fast weaponization of n‑days and treat patch availability as only one signal of risk.
  • Procurement leaders: with agent orchestration frameworks and inference/serving infrastructure representing a large share of AI‑related disclosures, procurement should scrutinize those components' exposure, particularly unauthenticated APIs and potential SSRF vectors.

GTIG's data paints a two‑part picture: AI‑assisted discovery appears to surface a larger share of medium‑risk, high‑impact flaws that can enable RCE, while exploitation activity to date has remained concentrated at the network perimeter and in rapidly weaponized n‑days. The concrete instances GTIG cites — including Hacktron AI's autonomous discovery of CVE‑2026‑1731, and the NetScaler zero‑days tracked by GTIG and Mandiant — underline that rapid weaponization and edge‑device risk are practical, present concerns rather than abstract possibilities. What remains to be seen is whether confirmed exploitation of AI infrastructure itself materializes with the same velocity as the n‑day pipeline GTIG describes.

Original story