AI-Found Vulnerabilities Double RCE Risk, Google Warns
Share
Vulnerabilities discovered with the assistance of artificial intelligence (AI) are disproportionately likely to enable remote code execution (RCE), according to new research from Google.
Published on 30 September 2026, a report by Google Threat Intelligence Group (GTIG) found that half of the vulnerabilities it identified as likely AI-discovered resulted in RCE. This compares to just 26% for other Common Vulnerabilities and Exposures (CVEs).
The findings come amidst a significant acceleration in both vulnerability disclosures and exploitation during 2026. Vulnerability disclosures doubled from 5,045 in January to 10,477 in July, reaching 10,740 by August of that year. Exploited vulnerabilities also rose from a monthly average of 10.5 in 2025 to 18 per month so far in 2026.
While zero-day exploitation saw only a marginal increase, from eight to 11 per month, with a spike to 22 in August, GTIG suggests that most of the overall growth in exploitation stems from the rapid weaponisation of n-day vulnerabilities. This process is potentially being aided by AI tools capable of analysing patches and proof-of-concept code.
GTIG’s analysis also indicated a shift in the risk profile of AI-discovered flaws. Medium-risk vulnerabilities accounted for 58% of likely AI-discovered flaws between January and August 2026, compared with 28% of those not attributed to AI. Conversely, low-risk flaws made up 39% and 69% respectively. Google attributes this distribution largely to researchers directing autonomous agents towards critical infrastructure rather than conducting broader, less targeted scans. The company also believes that public data currently undercounts the true number of AI-discovered vulnerabilities.
Confirmed exploitation of AI-discovered flaws is described as an early indicator rather than an established trend. One notable example cited is CVE-2026-1731, an unauthenticated command injection flaw in BeyondTrust Privileged Remote Access and Remote Support, which was autonomously discovered by Hacktron AI. A threat cluster exploited this vulnerability within four days of disclosure, with five more following within a week.
Overall, GTIG tracked more than 1,500 AI-related vulnerabilities disclosed in 2026. Agent orchestration frameworks accounted for 782 of these, while inference and serving infrastructure made up 212, nearly a quarter of which involved unauthenticated APIs or server-side request forgery (SSRF). However, only a handful of these have been confirmed as exploited, and GTIG has yet to observe zero-day exploitation of AI infrastructure itself.
Exploitation risk remains concentrated at the perimeter. Edge and security appliances were involved in 14% of exploited vulnerabilities in 2026, with over 65% of those edge flaws rated as high or critical risk. Charles Carmakal, CTO at Mandiant, emphasised the need for organisations to thoroughly examine their systems for compromise before patching, especially for actively exploited vulnerabilities.




Leave a Reply