AI Agents Find RCE Vulnerabilities at Double the Traditional Rate—And Attackers Exploit Them in Days Autonomous research agents identify remote code execution vulnerabilities at a 50% rate, nearly double the 26% seen across the broader CVE ecosystem, according to a GTIG report published September 30, 2026. The report cites CVE-2026-1731, a CVSS 9.9 pre-auth RCE in BeyondTrust remote support software found by Hacktron AI on January 31, 2026, which threat actors exploited within four days and five distinct clusters used by day seven to deploy SparkRAT, VShell backdoors, and DNS-tunneling exfiltration, with Cortex Xpanse telemetry showing over 16,400 exposed instances. Monthly vulnerability disclosures doubled from 5,045 in January 2026 to 10,740 in August 2026 and high-risk vulnerabilities rose 167% from 131 to 350, while 2,076 cumulative CVEs were tracked in the AI/LLM stack between January 2025 and August 2026, 782 of them in agent orchestration frameworks. Autonomous research agents are now identifying vulnerabilities that lead to remote code execution RCE at a rate of 50%, nearly double the 26% observed across the broader CVE ecosystem https://forkast.news/glossary/cve-common-vulnerabilities-and-exposures/ . This finding, detailed in the GTIG report https://cloud.google.com/blog/topics/threat-intelligence/vulnerability-discovery-and-exploitation-trends-in-the-ai-era published September 30, 2026, highlights a shift in how software flaws are surfaced and subsequently weaponized. The mechanics of this risk are visible in the case of CVE-2026-1731, a CVSS 9.9 pre-auth RCE in BeyondTrust remote support software. Hacktron AI identified the vulnerability on January 31, 2026, through AI-enabled variant analysis. According to the company, their autonomous scans are designed to discover vulnerability classes and variants across enterprise software at scale. Within four days of disclosure, threat actors began exploiting the flaw. By the seventh day, five distinct threat clusters were active, utilizing the vulnerability to deploy SparkRAT, VShell backdoors, and conduct data exfiltration via DNS tunneling. Telemetry from Cortex Xpanse indicated over 16,400 exposed instances at the time, affecting sectors including financial services, healthcare, and government across multiple continents. The broader data suggests that the velocity of vulnerability management is failing to keep pace with automated discovery. Monthly vulnerability disclosures doubled from 5,045 in January 2026 to 10,740 in August 2026. High-risk vulnerabilities saw a 167% surge, rising from 131 to 350 in the same period. The GTIG report identifies the primary growth driver as the rapid weaponization of n-days, rather than a surge in zero-day exploits, which remained relatively stable at an average of 11 per month in 2026. AI-discovered vulnerabilities are also inverting traditional risk distributions. While conventional discovery methods yield 69% low-risk findings, AI agents shift the focus, with 58% of their discoveries categorized as medium threat risk and 4% as high, compared to 3% for conventional methods. The GTIG report notes that autonomous research agents excel at reasoning through complex semantic code paths and synthesizing dynamic proof harnesses, surfacing memory corruption and logic bypasses in core libraries and runtimes. Conversely, these agents currently under-index in lower-impact categories like information disclosure and data manipulation. The AI infrastructure itself has become a primary attack surface. Between January 2025 and August 2026, 2,076 cumulative CVEs were tracked within the AI/LLM stack, with over 1,500 occurring in the first eight months of 2026. Agent orchestration frameworks accounted for 782 of these, representing 50% of all AI-related flaws and a 347% surge. Specific vulnerabilities, such as CVE-2026-42271 in LiteLLM and CVE-2026-5027 and CVE-2025-3248 in Langflow, demonstrate active exploitation within this stack. These developments align with previous incidents tracked by Forkast. The DIVD Zammad breach https://forkast.news/an-autonomous-ai-agent-just-breached-a-vulnerability-disclosure-nonprofit-by-chaining-two-zammad-zero-days/ , the use of an AI agent as C2 in the CARBONATO Docker botnet https://forkast.news/carbonato-is-the-first-botnet-where-the-command-and-control-engine-is-an-ai-agent-and-it-has-been-running-since-october-2024/ , the DNS sandbox escape https://forkast.news/openai-misalignment-reports-portal-dns-sandbox-escape-the-2-5-hour-gap/ at OpenAI’s Misalignment Portal, and the $387.5 million Bitget theft https://forkast.news/the-bitget-breach-when-security-layers-become-attack-surfaces/ via a security appliance zero-day all underscore the increasing integration of AI in both offensive and defensive operations. Grunewald, Mazumdar, and Vanderlee state that industry data on AI-augmented discovery is currently incomplete. The baseline is still under construction. However, existing metrics confirm that the interval between automated discovery and automated exploitation has compressed to days. For enterprise security teams, this velocity gap represents the primary structural challenge.