Google: half of AI-discovered vulnerabilities lead to remote code execution, as monthly CVE disclosures double

On September 30, 2026, the Google Threat Intelligence Group (GTIG) published “Vulnerability Discovery and Exploitation Trends in the AI Era,” by Robin Grunewald, Supriya Mazumdar and Kelli Vanderlee. It measures what the surge of AI-assisted bug finding has done to the vulnerability pipeline. Monthly CVE disclosures roughly doubled, from 5,045 in January 2026 to 10,740 in August, and GTIG counted 141 distinct vulnerabilities exploited in the wild from January to August 2026, already more than the 127 for all of 2025.

The headline finding is about severity. Of the CVEs GTIG classes as discovered by AI, 50% lead to remote code execution, against 26% of vulnerabilities found by other means, and AI-found bugs skew toward medium rather than low risk. Its case study is CVE-2026-1731, an unauthenticated command injection in BeyondTrust Remote Support and Privileged Remote Access found autonomously by the Hacktron AI research agent: the first threat cluster was exploiting it four days after disclosure, and five more had joined by day seven. GTIG also counts more than 1,500 AI-stack CVEs disclosed in January to August 2026, with agent orchestration frameworks such as Flowise, Langflow, LangChain, Dify and CrewAI accounting for 782 of them.

Why it matters: it is a quantitative answer to the question of whether AI vulnerability discovery helps defenders or attackers more. The volume of disclosures has outrun patching capacity, the bugs AI finds are disproportionately the dangerous kind, and the tools used to build agents have become the single largest category of AI-related flaws. GTIG’s recommendation is to shift from mass patching to threat-intelligence-driven triage.

What it does not show: only 0.23% of 2026 disclosures - roughly 1 in 431 - were seen exploited, so the growth in volume has not translated into a proportional flood of attacks. The split between AI-discovered and other CVEs depends on how GTIG attributes discovery, and the exploitation figures reflect what Google could observe.