The pace of vulnerability disclosures has accelerated dramatically through 2026, with monthly reports reaching 10,740 in August according to findings released Wednesday by Google's Threat Intelligence Group (GTIG). The trajectory shows a sharp climb from 5,045 disclosures in January, crossing the 10,000 threshold in both July and August.
Artificial intelligence is fundamentally reshaping the vulnerability ecosystem. "We found that AI is measurably changing not just the pace of vulnerability discovery and exploitation, but also the types and typical risk profiles of vulnerabilities that are being discovered," the researchers said. The eight-month period has already seen more exploited vulnerabilities than the entirety of 2025, with 141 cases this year compared to 127 last year.
N-Days Over Zero-Days
Rather than a surge in previously unknown zero-day exploits, the vulnerability spike stems from rapid weaponization of known flaws. GTIG's analysis shows that "the increase in vulnerability exploitation in 2026 is driven by the rapid, targeted weaponization of high-risk exploits in the wild rather than a flood of new zero-days." Attackers are leveraging AI tools to automate the analysis of software patches and publicly disclosed vulnerabilities, enabling faster exploitation of already-known bugs.
Kelli Vanderlee, senior analyst at GTIG, indicated that this trend will likely persist. According to the researchers, "It is possible that threat actors are finding it more accessible or efficient to use LLMs and AI tools to automate analysis of differences between product versions, patches, vulnerability disclosure announcements, and Proof-of-Concept (POC) code to rapidly weaponize n-days, rather than to discover new zero-days."
Case Study: BeyondTrust Vulnerability
Google highlighted CVE-2026-1731, a flaw in BeyondTrust software that was autonomously discovered by the AI research agent Hacktron AI and flagged by federal cyber defenders in February. Following public disclosure, threat actors moved with striking speed to weaponize the vulnerability in targeted campaigns against enterprise networks.
"Within four days of public disclosure, GTIG observed a threat cluster exploiting this vulnerability, followed by five additional threat clusters within seven days of public disclosure," the researchers said. The coordinated exploitation activity included privilege escalation, data theft, and deployment of secondary malware including SNOWLIGHT, SPARKRAT, and cryptominers.
The incident demonstrates that autonomous AI research agents, when focused on critical infrastructure entry points, "demonstrate a formidable capacity to uncover high-severity flaws." These tools are primarily identifying medium and high-risk vulnerabilities—those that would allow attackers to directly compromise targeted systems and networks with high reliability and at scale.
Vendor Concentration and Attack Patterns
A concentrated set of vendors has been the source of many disclosures this year, including router firmware maker Totolink and Oracle. Threat actors continue to prioritize perimeter appliances and exposed enterprise services, with edge and security appliances accounting for 14% of exploited vulnerabilities between January and August.
Broader Industry Trends
Google's findings align with data released last week by the Cybersecurity and Infrastructure Security Agency (CISA). More than 67,000 new CVEs have been published in 2026, with projections reaching 96,000 by year's end. The National Institute of Standards and Technology's National Vulnerability Database program reported a 263% increase in annual CVE submissions between 2020 and 2025, and submissions in the first quarter of 2026 were one-third higher than the same period in 2025, CISA noted.



