Google finds vulnerability disclosures doubled as AI changes which flaws get discovered
A new report out today from Google LLC’s Google Threat Intelligence Group finds that monthly software vulnerability disclosures doubled between January and August.
Not surprisingly, artificial intelligence is changing which flaws get discovered as well, and GTIG said half of those turned up by AI agents allow remote code execution.
August’s count of 10,740 vulnerability disclosures was more than twice January’s 5,045. GTIG cautioned that raw totals can overstate the threat, because automated identifier assignment in open-source ecosystems inflates them. Flaws with “Linux Kernel” in their descriptions accounted for about 5,000 records this year without producing a single zero-day exploited in the wild. High-risk disclosures on GTIG’s own scale rose 167% over the same months to 350 in August, and 128 of those came from Oracle Corp.’s quarterly patch release and Linux kernel network driver advisories.
By GTIG’s count, attackers exploited 141 newly disclosed vulnerabilities in the wild between January and August, more than the 127 recorded across all of 2025. Measured against disclosure volume the number is small, at about one flaw in 431, and the report notes that a single vendor’s disclosure cycle or one busy campaign can move the monthly figure.
Zero-day exploitation has averaged 11 a month so far this year against eight in 2025, with most months landing between eight and 12 until August brought 22. Zero-days, new vulnerabilities that haven’t been patched, still made up 62% of the 141 exploited flaws. Most of the growth, GTIG suggests, has come from n-days, meaning flaws that attackers go after once they are public and usually already patched.
Attackers may be using large language models to compare product versions and patches, the report says, so they can turn known flaws into working exploits quickly. Exploited high-risk flaws numbered 75 this year, up from 28 in all of 2025.
The report then turns to the vulnerabilities AI itself is finding. GTIG believes public data undercounts them, since vulnerability databases carry no standard tag for AI-assisted discovery. Large cloud and software-as-a-service providers also fix many AI-surfaced bugs in production without ever requesting an identifier, because those identifiers are normally reserved for software that customers have to patch themselves.
Among the vulnerabilities GTIG identified as likely AI discoveries, 58% fell in the moderate tier of its risk scale. Bugs found by people and conventional scanners land there about half as often, and 69% of those rate as low-risk. Researchers tend to aim their agents at critical infrastructure and sensitive privilege boundaries on purpose, and GTIG thinks that choice likely explains much of the gap.
Remote code execution shows up in only 26% of all other disclosures, and the report says AI’s higher rate likely stems from how well agents pick out memory corruption and logic bypasses deep in C and C++ code that static analyzers tend to miss.
GTIG treats confirmed attacks on AI-found flaws as an early indicator for now. The example it cites to show the risk is “not purely theoretical” is CVE-2026-1731. The bug lets an unauthenticated attacker inject operating system commands into BeyondTrust Corp.’s Privileged Remote Access and Remote Support products, and a research agent from Hacktron AI Inc. found it autonomously.
Within four days of disclosure in February, GTIG saw one threat cluster exploiting the flaw, and five more had joined within a week. The attackers went on to escalate privileges and steal data, and payloads they dropped included SNOWLIGHT and SPARKRAT malware plus cryptocurrency miners.
The report’s final section covers flaws in AI software. Of the 2,076 such disclosures GTIG has tracked since the start of 2025, more than 1,500 came this year. Agent orchestration frameworks such as Flowise and Langflow account for roughly half.
Visual workflow builders of that kind often include nodes that execute code, and attackers can reach them with prompt injection or a crafted workflow file. Inference and serving software such as vLLM, Ollama and LiteLLM drew 212 disclosures, and GTIG traced nearly a quarter of them to unauthenticated application programming interface endpoints or server-side request forgery.
GTIG has not yet observed zero-day exploitation of AI infrastructure. Only a handful of disclosed flaws have been exploited in the wild, among them a command injection bug in LiteLLM’s Model Context Protocol server preview endpoints and two in Langflow. In July, Sysdig Inc. documented an autonomous ransomware attack that broke in through the older of the Langflow flaws.
The Google unit expects discovery and exploitation to keep climbing over the short to medium term. Exploitation remains concentrated on perimeter appliances and exposed enterprise services, according to the report.
Its advice to organizations is to drop unprioritized mass patching and let threat intelligence decide what gets fixed first, with targeted defenses at the edge. Software vendors should run agentic AI code review before code ships, the report argues, naming Google’s own CodeMender as one option. If that becomes standard practice, growth in public disclosures could eventually slow, GTIG said.
Image: SiliconANGLE/GPT Image 2.5
A message from John Furrier, co-founder of SiliconANGLE:
Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.
- 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
- 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network
Are you an AWS customer? Support SiliconANGLE financially by buying your AWS services from our Marketplace portal page and links: https://siliconangle.com/aws-marketplace/
About SiliconANGLE Media
Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.