Overview of AI’s Influence on the Threat Landscape
New research from the Google Threat Intelligence Group (GTIG) highlights a significant acceleration in vulnerability discovery and exploitation, directly influenced by artificial intelligence (AI). This analysis, covering January 2025 through August 2026, indicates that AI is not only increasing the pace of vulnerability disclosures but also altering the typical risk profiles of discovered flaws. The findings underscore a measurable shift in the cybersecurity landscape, necessitating a re-evaluation of defensive strategies.
According to GTIG, the number of vulnerabilities disclosed monthly nearly doubled, rising from 5,045 in January 2026 to 10,740 in August 2026. Concurrently, the rate of in-the-wild exploitation also saw a substantial increase, moving from an average of 10.5 per month in 2025 to 18 per month in 2026. This trend suggests a more dynamic and challenging environment for security professionals seeking to protect their assets.
Technical Analysis of Vulnerability Dynamics
AI’s Impact on Vulnerability Discovery and Exploitation Dynamics
The GTIG report details a pronounced increase in vulnerability disclosures, with volumes peaking at 10,740 in August 2026. This raw disclosure volume, however, requires context. The research differentiates between general CVE inflation, often driven by automated processes in open-source ecosystems (e.g., thousands of Linux kernel CVEs without observed exploitation), and genuine threat risk increases.
Crucially, the increase in High-Risk vulnerabilities (based on GTIG’s internal risk ratings, not CVSS severity) is a key concern. These surged by 167% from 131 disclosures in January 2026 to 350 in August 2026. This rise was influenced by a widening pool of affected vendors and concentrated disclosure cycles. For instance, mass research disclosures targeting TOTOLINK consumer router firmware contributed 75 High-Risk flaws in April and May 2026. Furthermore, Oracle’s Critical Patch Updates for middleware like WebLogic and Coherence, combined with Linux kernel network driver advisories, added 128 High-Risk vulnerabilities in August alone, directly fueling growth in Remote Code Execution (RCE) vulnerabilities. AI-assisted discovery methods are finding proportionally fewer Low-Risk vulnerabilities, more Moderate-Risk vulnerabilities, and a higher incidence of RCEs, indicating a shift towards more impactful findings.
In terms of in-the-wild exploitation, GTIG observed 141 distinct vulnerabilities exploited between January and August 2026, surpassing the total of 127 for the entirety of 2025. This includes a marginal increase in trends in zero-day exploitation, which grew from an average of 8 per month in 2025 to 11 per month in 2026. Despite these increases, the proportion of exploited vulnerabilities remains small—approximately 0.23% of all disclosed vulnerabilities in 2026. However, since May 2026, the expansion of CVE exploitation has closely mirrored disclosure growth, scaling in tandem with the overall vulnerability landscape rather than outpacing it.
Actionable Recommendations and Mitigations
The accelerating pace of vulnerability discovery and exploitation necessitates a strategic shift in defensive postures. Organizations must transition away from undifferentiated mass-patching toward a more refined, threat-intelligence-driven triage for vulnerabilities. This approach involves prioritising patches based on active exploitation, the severity of the flaw (especially RCEs), and the potential impact on an organization’s specific environment.
Key recommendations include:
- Prioritise Threat-Intelligence-Driven Triage: Leverage current threat intelligence to identify and remediate the vulnerabilities that pose the most immediate and significant risk, rather than attempting to patch every disclosed flaw simultaneously.
- Implement Targeted Edge-Defense: Focus defensive efforts on perimeter systems and critical assets that are most exposed to observed exploitation trends.
- Adopt Automated, Agentic Remediation: Employ automation to accelerate the patching process and reduce the window of opportunity for attackers, particularly for high-risk and actively exploited vulnerabilities.
- Monitor RCE Vulnerabilities: Given AI’s propensity to discover more RCE flaws, organizations should place a heightened emphasis on identifying and mitigating these specific types of vulnerabilities. These often lead to the most severe impacts, including full system compromise.
Related: SharePoint RCE via CVE-2026-55040 & CVE-2026-63520: Patch Now, Threat Recap: Unpatched Exploits, Citrix Bleed 2, AI Attacks