AI Shifts Vulnerability Discovery
A newly discovered AI agent just autonomously uncovered a critical, unauthenticated command injection flaw.

A newly discovered AI agent just autonomously uncovered a critical, unauthenticated command injection flaw. This surge occurred as GTIG recorded 141 distinct exploited vulnerabilities in those first eight months, surpassing the 127 tracked throughout 2025.
Half of these vulnerabilities identified as likely discovered by AI result in remote code execution, compared to just 26% found by other means. Of these AI-discovered flaws, 39% were rated Low Risk and 58% Medium Risk, compared to 69% Low and 28% Medium for non-AI flaws. Zero-day exploitation also experienced a minor increase, rising from a monthly average of 8 in 2025 to 11 in 2026.
However, despite these rising numbers, only 0.23% of all disclosed vulnerabilities in 2026 were actually observed exploited in the wild. The higher severity of AI-discovered flaws likely reflects how research programs deploy AI agents to audit critical infrastructure and sensitive privilege boundaries. One thing remains unclear. The risk classifications (Low, Medium, High) cited in the report are based on GTIG's proprietary threat-risk ratings, which differ from the industry-standard Common Vulnerability Scoring System (CVSS) severity scores.
The risk classifications (Low, Medium, High) cited in the report are based on GTIG's proprietary threat-risk ratings, which differ from the industry-standard Common Vulnerability Scoring System (CVSS) severity scores.
Read the original reporting: https://www.helpnetsecurity.com/2026/10/01/vulnerabilities-ai-finds/
Sources
- Help Net SecurityPage not found - Help Net Security
- Google CloudVulnerability Discovery and Exploitation Trends in the AI Era
- Help Net SecurityThe vulnerabilities AI finds are the ones attackers want
- SecurityWeekGoogle: AI Is Changing the Pace and Profile of Vulnerability Discovery
- The RecordGoogle: Vulnerability disclosures double to 10,000 per month as AI fuels exploitation
- Infosecurity MagazineAI-Found Vulnerabilities More Likely to Enable RCE, Google Says
Verified claims
Written by The Quiet Search. Method: /about.