VYPR
researchPublished Jul 28, 2026· 1 source

AI-Found Vulnerabilities Show Modest Real-World Exploitation Rate, Research Finds

Despite significant hype, AI-assisted vulnerability discovery has not yet led to a surge in real-world exploits, with new research indicating a similar exploitation rate to traditional methods.

New research from VulnCheck has analyzed the real-world impact of AI-assisted vulnerability discovery, finding that the vast majority of flaws identified by AI tools are not being exploited by attackers. The study focused on publicly attributed AI-assisted vulnerability discoveries from Anthropic's Project Glasswing and the Berkeley Vulnerability Research Initiative, cross-referencing them against VulnCheck's extensive database of known exploited vulnerabilities (KEV).

The findings reveal that out of 1,061 analyzed AI-discovered vulnerabilities, only 14, or a mere 1.3 percent, have been confirmed as exploited in the wild. This rate is strikingly similar to the exploitation rate observed across all vulnerabilities in VulnCheck's dataset, suggesting that AI's current primary contribution is in increasing the volume of discovered flaws rather than the proportion of those flaws that become actively weaponized.

This contrasts sharply with some of the more sensational predictions surrounding AI's role in cybersecurity. Anthropic's Project Glasswing, for instance, was unveiled with considerable fanfare and warnings that AI-driven vulnerability discovery could empower attackers to compromise systems, disrupt operations, and steal data on an unprecedented scale. While Claude Mythos, the AI model behind Glasswing, reportedly identified over 23,000 vulnerability candidates, the public disclosure and exploitation data for these findings remain remarkably sparse.

VulnCheck's analysis further highlights this gap, noting that only 126 of these AI-identified candidates have been assigned CVE identifiers, and critically, only one has been confirmed as exploited in the wild. Anthropic's own public disclosure ledger has shown minimal activity since the project's launch, indicating a significant lag between AI-driven discovery and actionable, exploited vulnerabilities.

However, the research does not dismiss the value of AI in vulnerability research. Patrick Garrity, a security researcher at VulnCheck, stated that AI-assisted vulnerability discovery "clearly has value for both attackers and defenders." He emphasized that the data does not suggest AI-discovered vulnerabilities are inherently more likely to be exploited. Instead, AI is seen as a powerful tool that can significantly boost the efficiency of human researchers, enabling them to uncover more flaws and giving defenders a better opportunity to patch them proactively.

Garrity cautioned against declaring the threat of AI-driven exploitation entirely overblown, but he did suggest that current rhetoric has outpaced the available evidence. The "data so far... suggests that AI-assisted vulnerability discovery and frontier capabilities have been overhyped relative to the evidence available today," he wrote. The impact, while real, has been modest, rather than the apocalyptic scenario some had envisioned.

Meanwhile, traditional exploitation vectors remain a significant concern. VulnCheck identified 495 known exploited vulnerabilities in the first half of 2026, with content management systems and network edge devices continuing to be prime targets. The research also points to AI products themselves becoming increasingly attractive targets as attackers seek to exploit the rapidly expanding AI software ecosystem.

In conclusion, while AI is undoubtedly transforming the landscape of vulnerability research by accelerating discovery, it has not yet ushered in an era of widespread, AI-generated exploitation. The focus remains on the quality and exploitability of vulnerabilities, regardless of how they are found, underscoring the continued importance of robust patching and defense strategies.

Synthesized by Vypr AI