AI-assisted security tools are finding more bugs, but the threat level has not changed AI-assisted security tools like Anthropic's Project Glasswing and Microsoft's MDASH discovered 1,061 vulnerabilities in the first half of 2026, but only 14 (1.3%) were exploited in the wild, matching the overall exploitation rate, according to a VulnCheck report released Tuesday. The findings suggest AI-discovered bugs are not inherently more exploitable, though the trend may shift as major models launched in April and May 2026 ramp up. Meanwhile, average time to exploitation after CVE publication dropped from 120 days in 2025 to 80 days in H1 2026, and content management systems accounted for nearly one-third of exploited vulnerabilities. AI-assisted security tools are finding more bugs, but the threat level has not changed AI systems like Anthropic’s Project Glasswing https://cyberscoop.com/tag/project-glasswing/ and Microsoft’s MDASH https://cyberscoop.com/microsoft-ai-cybersecurity-project-perception/ are aiding in the discovery of vulnerabilities, filling the ever-growing pool of defects that defenders have to address before exploitation occurs. Yet, through the first half of 2026, these vulnerabilities were no more or less likely to be exploited than all vulnerabilities disclosed during that period, VulnCheck said in a report https://www.vulncheck.com/blog/state-of-exploitation-1h-2026 Tuesday. Concerns remain high about AI https://cyberscoop.com/tag/artificial-intelligence-ai/ -discovered vulnerabilities https://cyberscoop.com/tag/vulnerabilities/ fueling more attacks, but VulnCheck’s review of exploitation data shows that those fears are unfounded, at least so far. Patrick Garrity, security researcher at VulnCheck and report author, identified 1,061 vulnerabilities attributed to AI-assisted discovery during the first six months of the year. Of those vulnerabilities discovered by AI, 14 1.3% were exploited in the wild, a breakdown that aligns with the exploitation rate researchers observed across all vulnerabilities during the same period. “While AI-assisted vulnerability discovery clearly has value for both attackers and defenders, the data does not suggest that AI discovered vulnerabilities are inherently more likely to be exploited than those found through traditional methods,” Garrity wrote. While AI’s contribution to actively exploited vulnerabilities was muted in the first half of the year, it’s too soon to assume that trend will continue. Moreover, none of these major vulnerability-hunting models were running for that full period. Project Glasswing rolled out in April https://cyberscoop.com/project-glasswing-anthropic-ai-open-source-software-vulnerabilities/ , while Microsoft’s MDASH and OpenAI’s Daybreak https://cyberscoop.com/openai-daybreak-gpt-5-5-anthropic-mythos-cybersecurity/ were both unveiled in May. The upward trend in Microsoft’s monthly Patch Tuesday https://cyberscoop.com/tag/patch-tuesday/ indicates how much the floodgates might open through the remainder of the year as AI models discover more vulnerabilities. The company’s July security update contained an all-time-record of 622 vulnerabilities https://cyberscoop.com/microsoft-patch-tuesday-july-2026/ , besting the previous record-breaking June update with 206 vulnerabilities https://cyberscoop.com/microsoft-patch-tuesday-june-2026/ . VulnCheck https://cyberscoop.com/tag/vulncheck/ ’s state of exploitation report also found that vulnerabilities were exploited much faster after CVE publication, speeding up from an average of 120 days in 2025 to 80 days during the first half of the year. The intelligence firm also determined which technology categories were actively exploited most often. Content management systems accounted for nearly one-third of the 495 known exploited vulnerabilities VulnCheck identified during the first half of 2026. Network edge devices were responsible for almost 14%, followed by operating systems at nearly 9%, server software at 8%, and AI products — an emerging attack surface — at almost 6%.