# Google: Vulnerability disclosures double to 10,000 per month as AI fuels exploitation

> Source: <https://therecord.media/google-vulnerabilities-cyberattacks-ai>
> Published: 2026-09-30 19:00:00+00:00

# Google: Vulnerability disclosures double to 10,000 per month as AI fuels exploitation

Vulnerability disclosures doubled between January and August, reaching a new peak of 10,740 last month, Google’s Threat Intelligence Group (GTIG) said Wednesday.

Total vulnerability disclosures began the year at 5,045 in January and had jumped to more than 10,000 for July and August.

“We found that AI is measurably changing not just the pace of vulnerability discovery and exploitation, but also the types and typical risk profiles of vulnerabilities that are being discovered,” the researchers said.

They noted that beyond the overall number of bugs being found, the number of distinct vulnerabilities disclosed and exploited during the eight month period surpassed the totals for all of 2025. There have already been 141 exploited vulnerabilities this year after 127 last year.

In a report on Wednesday, GTIG said the increase in vulnerability exploitation in 2026 “is driven by the rapid, targeted weaponization of high-risk exploits in the wild rather than a flood of new zero-days.” Zero-days are vulnerabilities that are exploited before they are known to vendors and n-days are vulnerabilities that have been patched and publicly disclosed.

The researchers found that hackers are getting better at using artificial intelligence to scan patches and exploit critical bugs. Kelli Vanderlee, senior analyst at GTIG, said they expect that AI-assisted vulnerability discovery and exploitation will continue to grow in the short-to medium-term.

“It is possible that threat actors are finding it more accessible or efficient to use LLMs and AI tools to automate analysis of differences between product versions, patches, vulnerability disclosure announcements, and Proof-of-Concept (POC) code to rapidly weaponize n-days, rather than to discover new zero-days,” the researchers said.

 As an example, Google pointed to CVE-2026-1731 — a vulnerability in BeyondTrust software [spotlighted](https://www.cisa.gov/news-events/alerts/2026/02/13/cisa-adds-one-known-exploited-vulnerability-catalog) by federal cyber defenders in February. The bug was found autonomously by a third-party research agent Hacktron AI. 

After it was disclosed, Google’s researchers said it saw threat actors “weaponize this vulnerability in targeted initial-access campaigns to bypass enterprise perimeters.”

“More specifically, within four days of public disclosure, GTIG observed a threat cluster exploiting this vulnerability, followed by five additional threat clusters within seven days of public disclosure,” they said.

“GTIG observed these threat actors collectively conduct a variety of post-exploitation activities, including privilege escalation, data exfiltration, and dropping secondary payloads including SNOWLIGHT, SPARKRAT, and cryptominers.”

The case illustrated that when directed at critical attack surfaces, autonomous research agents “demonstrate a formidable capacity to uncover high-severity flaws.”

AI agents are being used mostly to find medium and high-risk vulnerabilities. Vanderlee said they classify a bug as high-risk if exploitation would enable attackers to have a notable, direct impact to the security of targeted devices and networks without needing to overcome any major mitigating factors.

“Reliability of exploitation is expected to be high and can typically be done on a wide scale," she added.

The researchers said many of the disclosures this year have come from a handful of vendors, including router firmware company Totolink and Oracle.

Threat actors continue to focus exploitation activity on perimeter appliances and exposed enterprise services, with 14% of vulnerabilities exploited between January and August affecting edge and security appliances.

 The report mirrors findings [released](https://www.cisa.gov/sites/default/files/2026-09/cve-program-establishing-a-quality-era-framework-508c.pdf) last week by the Cybersecurity and Infrastructure Security Agency (CISA) that more than 67,000 new CVEs have been published in 2026. Experts project a total of 96,000 new CVEs by the end of the year. 

The National Institute of Standards and Technology’s National Vulnerability Database program reported a 263% increase in annual CVE submissions between 2020 and 2025, with submissions in the first three months of 2026 one-third higher than during the same period in 2025, CISA said.

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
