Download Privacy Needle App

Type to search

Cybersecurity

AI-Found Vulnerabilities Double RCE Risk, Google Warns

Share

Vulnerabilities discovered with the assistance of artificial intelligence (AI) are disproportionately likely to enable remote code execution (RCE), according to new research from Google.

Published on 30 September 2026, a report by Google Threat Intelligence Group (GTIG) found that half of the vulnerabilities it identified as likely AI-discovered resulted in RCE. This compares to just 26% for other Common Vulnerabilities and Exposures (CVEs).

The findings come amidst a significant acceleration in both vulnerability disclosures and exploitation during 2026. Vulnerability disclosures doubled from 5,045 in January to 10,477 in July, reaching 10,740 by August of that year. Exploited vulnerabilities also rose from a monthly average of 10.5 in 2025 to 18 per month so far in 2026.

While zero-day exploitation saw only a marginal increase, from eight to 11 per month, with a spike to 22 in August, GTIG suggests that most of the overall growth in exploitation stems from the rapid weaponisation of n-day vulnerabilities. This process is potentially being aided by AI tools capable of analysing patches and proof-of-concept code.

GTIG’s analysis also indicated a shift in the risk profile of AI-discovered flaws. Medium-risk vulnerabilities accounted for 58% of likely AI-discovered flaws between January and August 2026, compared with 28% of those not attributed to AI. Conversely, low-risk flaws made up 39% and 69% respectively. Google attributes this distribution largely to researchers directing autonomous agents towards critical infrastructure rather than conducting broader, less targeted scans. The company also believes that public data currently undercounts the true number of AI-discovered vulnerabilities.

Confirmed exploitation of AI-discovered flaws is described as an early indicator rather than an established trend. One notable example cited is CVE-2026-1731, an unauthenticated command injection flaw in BeyondTrust Privileged Remote Access and Remote Support, which was autonomously discovered by Hacktron AI. A threat cluster exploited this vulnerability within four days of disclosure, with five more following within a week.

Overall, GTIG tracked more than 1,500 AI-related vulnerabilities disclosed in 2026. Agent orchestration frameworks accounted for 782 of these, while inference and serving infrastructure made up 212, nearly a quarter of which involved unauthenticated APIs or server-side request forgery (SSRF). However, only a handful of these have been confirmed as exploited, and GTIG has yet to observe zero-day exploitation of AI infrastructure itself.

Exploitation risk remains concentrated at the perimeter. Edge and security appliances were involved in 14% of exploited vulnerabilities in 2026, with over 65% of those edge flaws rated as high or critical risk. Charles Carmakal, CTO at Mandiant, emphasised the need for organisations to thoroughly examine their systems for compromise before patching, especially for actively exploited vulnerabilities.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

You Might also Like

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.