OFICIAL Google Cloud Threat Intelligence

Vulnerability Discovery and Exploitation Trends in the AI Era

What happened
Based on Google Cloud Threat Intelligence · Sep 30, 2026

Google’s threat intelligence unit reports that AI is accelerating vulnerability discovery and exploitation, with disclosures and attacks nearly doubling since early 2026 and a surge in high-risk flaws.

Vulnerability Discovery and Exploitation Trends in the AI Era
Google Cloud Threat Intelligence — Google
Key points
·
Vulnerability disclosures rose from 5,045 in January 2026 to 10,740 in August 2026, per GTIG analysis of January 2025–August 2026 data.
·
High-Risk vulnerability disclosures surged 167% from January to August 2026, reaching 350 in August, driven by Oracle’s CPU and TOTOLINK router flaws.
·
Exploitation of High-Risk vulnerabilities more than doubled from 28 in 2025 to 75 in the first eight months of 2026.
Key numbers
·
The report highlights a 167% increase in High-Risk vulnerability disclosures, rising from 131 in January 2026 to 350 in August 2026, though these still represent only 3% of all disclosures.
·
5 per month in 2025 to 18 per month in 2026, with 141 distinct vulnerabilities exploited from January to August 2026 exceeding the total for all of 2025.
·
23% of disclosures, indicating that most disclosed flaws are not actively targeted by threat actors.

Google Threat Intelligence Group (GTIG) found that the number of vulnerabilities disclosed per month more than doubled from 5,045 in January 2026 to 10,740 in August 2026, driven in part by automated CVE numbering policies in open-source ecosystems. The analysis, covering January 2025 through August 2026, shows that raw disclosure volumes can be inflated by mass assignments, such as 5,000 Linux Kernel-related CVEs with no observed exploitation during the period. GTIG emphasizes that threat intelligence context is essential to interpret these figures accurately, as not all disclosures translate to meaningful security risk.

The report highlights a 167% increase in High-Risk vulnerability disclosures, rising from 131 in January 2026 to 350 in August 2026, though these still represent only 3% of all disclosures. The surge was fueled by concentrated vendor disclosure cycles, including Oracle’s quarterly Critical Patch Update and mass research disclosures against consumer router firmware like TOTOLINK, which added 75 High-Risk flaws in April and May 2026.

Exploitation of vulnerabilities grew from an average of 10.5 per month in 2025 to 18 per month in 2026, with 141 distinct vulnerabilities exploited from January to August 2026 exceeding the total for all of 2025. However, the proportion of exploited vulnerabilities remains minimal, at 0.23% of disclosures, indicating that most disclosed flaws are not actively targeted by threat actors.

GTIG notes that zero-day exploitation increased marginally from 8 per month in 2025 to 11 per month in 2026, with a notable spike to 22 in August 2026. The majority of exploited vulnerabilities (62%) during the period were zero-days, but the primary driver of exploitation growth appears to be the rapid weaponization of n-days, facilitated by AI tools that automate analysis of patches and disclosures.

Original source → Deals on Clipraptor.com →