AI Accelerates Vulnerability Discovery and Exploitation, Mandiant Reports
Mandiant's GTIG analysis reveals AI is doubling vulnerability disclosures and increasing exploitation rates, shifting the landscape towards more consequential flaws.

Google Threat Intelligence Group (GTIG) has observed a significant acceleration in both the discovery and exploitation of software vulnerabilities, directly attributing this trend to the increasing influence of artificial intelligence (AI). Their analysis, covering January 2025 through August 2026, indicates that AI is not only speeding up the process but also altering the nature of vulnerabilities being uncovered, leading to a greater proportion of high-risk flaws.
The most striking finding is the doubling of monthly vulnerability disclosures throughout 2026. Starting the year with 5,045 disclosed vulnerabilities in January, the number surged to over 10,000 by July and August. While this raw number can be inflated by automated assignment policies, the trend in high-risk vulnerabilities is more concerning. GTIG reported a 167% growth in high-risk disclosures from January to August 2026, climbing from 131 to 350 per month. These high-risk flaws, though still a small percentage of the total, are increasingly leading to critical outcomes like remote code execution (RCE).
AI's impact is also evident in the exploitation rates. The number of exploited vulnerabilities increased from an average of 10.5 per month in 2025 to 18 per month in the first eight months of 2026. While zero-day exploitation saw only a marginal increase, the overall trend suggests that vulnerabilities are being weaponized more rapidly. Notably, the proportion of disclosed vulnerabilities that are actually exploited in the wild remains very small, around 0.23% in 2026. However, the growth in exploitation volume is now closely mirroring the growth in disclosure volume, indicating a more synchronized threat landscape.
The analysis highlights specific vendor disclosure cycles that contributed to the surge in high-risk vulnerabilities. For instance, mass research disclosures against TOTOLINK consumer router firmware in April and May 2026 added 75 high-risk flaws. Similarly, Oracle's quarterly Critical Patch Update (CPU) and Linux kernel network driver advisories in June, July, and August contributed significantly to the rise in RCE vulnerabilities, accounting for nearly 37% of all high-risk disclosures in August alone.
Beyond sheer volume, AI appears to be influencing the *type* of vulnerabilities discovered. AI-assisted discovery is proportionally finding fewer low-risk vulnerabilities and more moderate-risk and RCE-enabling flaws. This suggests that AI tools are becoming more adept at identifying complex and impactful security weaknesses, potentially lowering the barrier for sophisticated attacks.
In response to this evolving threat landscape, GTIG recommends a strategic shift away from unprioritized mass-patching. Organizations are urged to adopt threat-intelligence-driven triage processes. This approach involves combining targeted edge defenses with automated, agentic remediation capabilities to more effectively manage the increased risk posed by the rapid pace of vulnerability discovery and exploitation.
GTIG anticipates that these trends will continue in the short to medium term, underscoring the need for proactive and intelligent security strategies. The findings serve as a critical warning for organizations to adapt their vulnerability management programs to the realities of an AI-augmented threat environment.