← AI Switchboard
RESEARCH · October 1, 2026
Sep 30

Google's threat group finds half of AI-discovered software flaws let attackers run code remotely, twice the rate across all CVEs

Monthly vulnerability disclosures doubled between January and July 2026, and exploited flaws this year already outnumber all of 2025.

Google Threat Intelligence Group published “Vulnerability Discovery and Exploitation Trends in the AI Era” on 30 September, by Robin Grunewald, Supriya Mazumdar and Kelli Vanderlee. Its main finding is about the kind of flaws AI finds, not just how many: “Exactly 50% of all AI-discovered vulnerabilities result in Remote Code Execution (RCE), compared to just 26% across the broader CVE ecosystem.” Remote code execution is the most serious class, where an attacker can run their own code on the target machine.

Volume is up as well. Monthly vulnerability disclosures went from 5,045 in January 2026 to 10,477 in July and 10,740 in August. The group counts 141 distinct vulnerabilities disclosed and exploited from January to August 2026, against 127 in the whole of 2025. Zero-days, flaws exploited before a fix exists, rose from an average of 8 a month in 2025 to 11 a month in 2026, with 22 in August alone.

AI software is a growing target in its own right: the report counts 2,076 AI-related CVEs from January 2025 to August 2026, more than 1,500 of them this year.

A caution on reading the headline figure. The report does not give a total number of AI-discovered vulnerabilities; the 50% is a share of the flaws Google could attribute to AI discovery, using lab and vendor records and advisories that credit autonomous agents. And the 26% is the rate across all CVEs, not specifically flaws found without AI.

  • Confirmed 50% of AI-discovered vulnerabilities lead to remote code execution, against 26% across the broader CVE ecosystem. Google Threat Intelligence Group
  • Confirmed Monthly disclosures 5,045 in January 2026 and 10,477 in July; 141 vulnerabilities disclosed and exploited January–August 2026 against 127 in all of 2025. Google Threat Intelligence Group
  • Confirmed 2,076 AI-related CVEs from January 2025 to August 2026, more than 1,500 of them in 2026. Google Threat Intelligence Group

Safety, security & governanceScience & research

Today in the October 1, 2026 edition · front page