{"slug": "ai-is-finding-twice-as-many-software-flaws-almost-none-get-exploited", "title": "AI is finding twice as many software flaws. Almost none get exploited.", "summary": "AI-discovered software vulnerabilities are surging at roughly twice last year's rate, but almost none are being exploited, according to a VulnCheck report. Of 1,061 vulnerabilities attributed to AI-assisted discovery in the first half of 2026, only 14 (1.3%) have been confirmed as exploited, matching the rate for all vulnerabilities. The findings challenge warnings that AI would enable attackers to exploit flaws faster than defenders can patch.", "body_md": "AI-discovered vulnerabilities are arriving at roughly twice last year’s rate. Almost none of them are being exploited.\n\nThe US National Vulnerabilities Database recorded 45,207 software flaws between January and 27 July, already approaching the whole of 2025, which was itself a record. On that trajectory the year ends at roughly double the 2025 total, [Bloomberg reported](https://www.bloomberg.com/news/articles/2026-07-27/ai-hunts-for-cyber-flaws-finding-record-numbers-in-tech-sector).\n\nThe individual tallies are extraordinary. Oracle patched 1,449 vulnerabilities in its July update against 309 in the same month last year. Microsoft’s July update fixed [a record 622 flaws](https://thenextweb.com/news/microsoft-patch-tuesday-record-ai-found-flaws), and credited AI discovery for the surge.\n\nThis is the moment the warnings pointed at. Attackers with frontier models, a flood of fresh holes, defenders unable to patch fast enough.\n\nIt has not happened.\n\n## Exploitation never followed discovery\n\nVulnerability intelligence firm VulnCheck examined every known exploited vulnerability it logged in the first half of 2026. It found 495, and the conclusion is blunt.\n\nAI-assisted discovery has been “overhyped relative to the evidence available today”, wrote Patrick Garrity, the security researcher who authored [the report](https://www.vulncheck.com/blog/state-of-exploitation-1h-2026).\n\nAcross two datasets, VulnCheck identified 1,061 vulnerabilities attributed to AI-assisted discovery. Fourteen of them, or 1.3%, have been confirmed as exploited.\n\nThat is roughly the rate for all vulnerabilities in the period, and lower than the historical average. AI-discovered vulnerabilities do not appear to draw attackers any more than the rest.\n\nThe ratio makes it starker. Known exploited vulnerabilities grew 10% against the previous six months. Published CVEs grew 45%. The share of CVEs that end up exploited has fallen to 1.4%, from a peak of 2.7% in late 2023.\n\nEarly exploitation has not scaled at all in absolute terms. Roughly 200 CVEs reached exploited status within 31 days of publication, against 196 in 2024 and 194 in 2025.\n\n## The ledger that stopped growing\n\nThe sharpest evidence concerns Anthropic, whose Project Glasswing did more than any other launch to raise the alarm.\n\nAnthropic opened a public disclosure ledger in May, saying Claude had identified 23,019 findings. We covered the scale at the time, when [Mythos found 10,000 flaws in a month](https://thenextweb.com/news/anthropic-glasswing-claude-mythos-10000-vulnerabilities) and patching could not keep up.\n\nVulnCheck went back to check what happened next.\n\nThe ledger has never grown beyond the 1,611 entries it launched with. Of those, 126 became published CVEs. One has been confirmed as exploited in the wild.\n\nMore than 150 findings have passed the disclosure deadline set out in Anthropic’s own Coordinated Disclosure Policy, Garrity writes, and the company has published no updates or new disclosures.\n\nGarrity has tracked those disclosures in a public repository since April, so the claim is checkable rather than rhetorical.\n\n## Who is actually finding the bugs\n\nMuch of the record volume is vendors finding their own flaws. Most of the vulnerabilities Google fixed in a recent Chrome update were reported internally rather than by outsiders.\n\nThat distinction carries the whole argument. A flaw a vendor finds and patches is a flaw an attacker never reaches.\n\nGarrity reads it the same way. Giving defenders frontier models is more likely to help them harden software than to help attackers get there first.\n\n## What did change\n\nTwo things moved, and neither is comforting.\n\nVulnerabilities now reach exploited status faster. The median time from CVE publication fell from 120 days in 2025 to 80 days in the first half of this year.\n\nCISA has responded with new guidance, recommending patching within three days where there is evidence of exploitation alongside high impact or public exposure.\n\nAI tools have also become targets. VulnCheck identified 28 known exploited vulnerabilities in AI systems and observed activity against 10 of them.\n\nIn the workflow tool LangFlow, attackers chained two flaws to gain access, harvested credentials likely intended for services such as OpenAI and Claude, deployed cryptominers and attempted to move laterally. Neither vulnerability has reached the federal catalogue.\n\nThe models themselves are part of that surface. OpenAI has confirmed its own agents [broke out of a sandbox and breached Hugging Face](https://thenextweb.com/news/openai-confirms-its-ai-broke-out-of-a-sandbox-and-breached-hugging-face).\n\n## The tools keep shipping regardless\n\nNone of this has slowed the market. Microsoft launched [Project Perception](https://thenextweb.com/news/microsoft-project-perception-agentic-security-cyber-model) on Monday, an agentic security system entering public preview on 3 August. Cisco has been [pointing small open-weight models at bug hunting](https://thenextweb.com/news/cisco-antares-open-weight-bug-hunting-ai-vulnerability).\n\nGarrity’s caveat is worth keeping. Exploitation evidence often surfaces long after disclosure, and the major bug-hunting models were not running for the full period. Glasswing arrived in April, Microsoft’s MDASH and OpenAI’s Daybreak in May.\n\nThe risk is not imaginary. On the evidence so far it is real but modest, and the loudest claim about it has a ledger that stopped updating.\n\n## Get the TNW newsletter\n\nGet the most important tech news in your inbox each week.", "url": "https://wpnews.pro/news/ai-is-finding-twice-as-many-software-flaws-almost-none-get-exploited", "canonical_source": "https://thenextweb.com/news/ai-discovered-vulnerabilities-exploitation-vulncheck-anthropic-ledger", "published_at": "2026-07-28 18:09:27+00:00", "updated_at": "2026-07-28 18:58:46.211322+00:00", "lang": "en", "topics": ["artificial-intelligence", "ai-safety", "ai-policy"], "entities": ["VulnCheck", "Patrick Garrity", "Anthropic", "Project Glasswing", "Claude", "Oracle", "Microsoft", "CISA"], "alternates": {"html": "https://wpnews.pro/news/ai-is-finding-twice-as-many-software-flaws-almost-none-get-exploited", "markdown": "https://wpnews.pro/news/ai-is-finding-twice-as-many-software-flaws-almost-none-get-exploited.md", "text": "https://wpnews.pro/news/ai-is-finding-twice-as-many-software-flaws-almost-none-get-exploited.txt", "jsonld": "https://wpnews.pro/news/ai-is-finding-twice-as-many-software-flaws-almost-none-get-exploited.jsonld"}}