#78 · Briefing ·

AI Shifts Vulnerability Discovery

A newly discovered AI agent just autonomously uncovered a critical, unauthenticated command injection flaw.

AI agent uncovers critical flaw
AI-generated illustration. AI agent uncovers critical flaw

A newly discovered AI agent just autonomously uncovered a critical, unauthenticated command injection flaw. This surge occurred as GTIG recorded 141 distinct exploited vulnerabilities in those first eight months, surpassing the 127 tracked throughout 2025.

Half of these vulnerabilities identified as likely discovered by AI result in remote code execution, compared to just 26% found by other means. Of these AI-discovered flaws, 39% were rated Low Risk and 58% Medium Risk, compared to 69% Low and 28% Medium for non-AI flaws. Zero-day exploitation also experienced a minor increase, rising from a monthly average of 8 in 2025 to 11 in 2026.

However, despite these rising numbers, only 0.23% of all disclosed vulnerabilities in 2026 were actually observed exploited in the wild. The higher severity of AI-discovered flaws likely reflects how research programs deploy AI agents to audit critical infrastructure and sensitive privilege boundaries. One thing remains unclear. The risk classifications (Low, Medium, High) cited in the report are based on GTIG's proprietary threat-risk ratings, which differ from the industry-standard Common Vulnerability Scoring System (CVSS) severity scores.

The risk classifications (Low, Medium, High) cited in the report are based on GTIG's proprietary threat-risk ratings, which differ from the industry-standard Common Vulnerability Scoring System (CVSS) severity scores.

Read the original reporting: https://www.helpnetsecurity.com/2026/10/01/vulnerabilities-ai-finds/

Sources

Verified claims

Original reporting: https://www.helpnetsecurity.com/2026/10/01/vulnerabilities-ai-finds/

Written by The Quiet Search. Method: /about.

Related

Comments

Plain text only. New comments stay hidden until a person reviews them.