Skip to content
KO EN
AI 기술 Upcoming

AI-Discovered Vulnerabilities: Only 1.3% Exploited, Yet Attack Speed Accelerates

Artificial intelligence is transforming the way security vulnerabilities are discovered, but a new report suggests that the flood of AI-generated findings

Artificial intelligence is transforming the way security vulnerabilities are discovered, but a new report suggests that the flood of AI-generated findings may not translate into real-world risk. According to data from VulnCheck, a security firm that tracks vulnerability exploitation, only 1.3% of the 1,061 vulnerabilities identified with AI assistance during the first half of 2026 were confirmed to be exploited in actual attacks. That figure, representing just 14 cases, is roughly on par with the exploitation rate for all vulnerabilities, indicating that AI’s ability to find flaws does not necessarily mean those flaws are being weaponized.

What Happened: AI’s Security Findings vs. Real-World Exploitation

The report, compiled by VulnCheck’s Patrick Garrity, highlights a striking disparity between the volume of AI-discovered vulnerabilities and their practical impact. For instance, Anthropic’s Project Glasswing generated over 23,000 findings, but only 126 were published as official vulnerabilities, and just one was confirmed to be exploited. This suggests that while AI tools can scan code and identify potential weaknesses at scale, many of these findings may be false positives or low-severity issues that attackers do not prioritize. The sheer volume of data can overwhelm security teams, making it harder to focus on genuine threats.

However, the report also reveals a concerning trend: the speed at which vulnerabilities are exploited is accelerating. Half of all vulnerabilities now see their first confirmed exploitation within 80 days of disclosure, down from 120 days the previous year. Additionally, about 200 vulnerabilities were attacked within a month of disclosure, even as the total number of reported vulnerabilities continues to climb. This indicates that attackers are becoming faster at leveraging known flaws, putting pressure on organizations to patch more quickly.

Why It Matters: The Shifting Attack Surface

The report underscores a critical shift in the cybersecurity landscape. While AI is helping defenders find vulnerabilities, attackers are focusing on well-established targets. Website content management systems (CMS) account for a third of all confirmed attacks, suggesting that widely used platforms remain the primary entry points. Meanwhile, AI products themselves are emerging as a new attack surface, including model-building tools and agent interfaces. This is a double-edged sword: as organizations adopt AI, they may inadvertently expose themselves to new risks that traditional security measures are not yet equipped to handle.

XPLAIN AI interprets these findings as a wake-up call for the security industry. The metric of ‘AI-discovered vulnerabilities’ is not inherently a risk indicator; rather, it may be noise that distracts defenders from actual threats. Security teams could waste resources chasing false positives while missing critical signals. Therefore, organizations should shift their focus from the quantity of AI findings to the likelihood of actual exploitation, developing risk assessment frameworks that prioritize actionable intelligence.

Market Implications: Winners and Losers

The report’s insights have subtle but significant implications for the cybersecurity market. Companies that provide AI-powered security tools will need to differentiate themselves by their ability to filter out noise and prioritize real threats, rather than simply touting the number of vulnerabilities found. This could benefit firms like CrowdStrike and Palo Alto Networks that emphasize threat intelligence and automated response. Conversely, organizations relying on outdated CMS platforms or legacy infrastructure may face increased risk, as attackers continue to target these systems. This could drive demand for managed security services and patch management solutions.

On the other hand, companies developing AI products, such as Anthropic and OpenAI, may face heightened scrutiny as their tools become attack surfaces. This could lead to increased investment in securing AI models and interfaces, potentially benefiting specialized security startups. However, it also poses a risk: if AI products are perceived as insecure, adoption could slow. The report suggests that the market is at a crossroads, where the value of AI in security is measured not by discovery volume but by its ability to reduce actual risk.

Contrarian View and Uncertainties

It is important to note that this report is based on data from a single source, and the findings may not be universally applicable. The exploitation rate of 1.3% could change as AI technology evolves and attackers adapt. For instance, if AI becomes more adept at finding high-severity vulnerabilities, the exploitation rate could rise. Conversely, if defenders improve their patch management, the rate might remain low. Therefore, it would be premature to conclude that AI security tools are ineffective or that the threat is minimal. The data should be seen as a snapshot in time, not a definitive trend.

Furthermore, the report does not account for the potential of AI to be used by attackers themselves. While AI-assisted discovery may not lead to many exploits, malicious actors could use AI to identify vulnerabilities more efficiently, potentially increasing the exploitation rate in the future. This is an area that requires further research and monitoring.

What to Watch Next

Going forward, key indicators to monitor include the time-to-exploitation metric, which is currently 80 days. If this continues to shrink, it would signal that attackers are becoming more efficient, likely driving demand for automated patch management and threat intelligence. Additionally, an increase in attacks targeting AI products would validate the concern that AI is a growing attack surface, potentially leading to new regulations and security standards. Conversely, if the exploitation rate remains low, organizations may reconsider their investments in AI security tools, focusing instead on fundamental hygiene practices like patch management and network segmentation.

In conclusion, the VulnCheck report provides a valuable reality check on the role of AI in cybersecurity. It highlights the gap between discovery and exploitation, while also underscoring the accelerating pace of attacks. For security professionals, the takeaway is clear: prioritize based on risk, not volume, and stay vigilant as the threat landscape evolves.

#AISecurity #VulnerabilityManagement #CyberThreats #VulnCheck #SecurityStrategy #AIAgents #PatchManagement #CyberResilience

Sources

Written by: XPLAIN AI Editorial Team · Reviewed by: XPLAIN AI Editorial Desk
This content was drafted with AI assistance based on publicly available sources and reviewed under XPLAIN AI's editorial standards.

Found an error? Request a correction →