VYPR
researchPublished Jul 28, 2026· 1 source

AI Fuels Vulnerability Discovery Surge, But Exploitation Rates Remain Stable

Analysis of the first half of 2026 reveals a significant increase in newly discovered vulnerabilities, largely attributed to AI, yet the rate at which these flaws are exploited in the wild has not kept pace.

The cybersecurity landscape is grappling with an unprecedented surge in vulnerability discovery, with artificial intelligence emerging as a key driver behind this exponential growth. However, despite the sheer volume of newly identified flaws, the rate of real-world exploitation has remained remarkably steady, according to an analysis of Common Vulnerabilities and Exposures (CVE) data from the first half of 2026. This trend suggests that while AI is accelerating the identification of security weaknesses, it has not yet translated into a proportional increase in active exploitation by threat actors.

VulnCheck, a vulnerability intelligence platform, reported that the number of newly assigned CVEs that were also confirmed as known exploited vulnerabilities (KEVs) within 31 days stayed consistent year-over-year, with 196 in 2024, 194 in 2025, and 200 in the first half of 2026. This stability in exploitation rates is occurring even as AI-assisted discovery contributes to a much larger pool of identified vulnerabilities. Of the 1,061 vulnerabilities attributed to AI-assisted discovery, only 1.3% have been confirmed as exploited in the wild, a rate comparable to the overall exploitation rate for all vulnerabilities during the same period.

Patrick Garrity, a security researcher at VulnCheck and author of the report, explained that attacker resources and operational objectives naturally limit the number of vulnerabilities they can actively exploit. Threat actors tend to be opportunistic, prioritizing flaws that best serve their goals rather than attempting to leverage every newly discovered vulnerability. Consequently, an increase in vulnerability disclosures does not automatically lead to a proportional rise in exploit activity. VulnCheck's own KEV list, which is partially derived from its honeypots, currently identifies 200% more exploited vulnerabilities in the wild than the U.S. Cybersecurity and Infrastructure Security Agency (CISA).

Concerns about a potential "vulnocalypse" – a moment of drastically accelerating flaw discovery, potentially instigated by AI – intensified following Anthropic's release of its Mythos large language model in April 2026. This model demonstrated an unprecedented ability to chain together vulnerabilities into exploit chains. Despite these advancements, the volume of disclosed vulnerabilities has "gone vertical while exploitation has not," noted Jerry Gamblin, co-author of a recent report from FIRST (Forum of Incident Response and Security Teams).

FIRST's data corroborates VulnCheck's findings, showing a significant leap in CVEs during the first half of 2026, with a total of 35,364 new CVEs, approximately 50% of which are rated as critical or high severity. However, less than 1% of these newly cataloged flaws, totaling 85, have appeared in CISA's KEV catalog. This suggests that the surge in vulnerability data presents more of a triage challenge for defenders than an immediate need to patch every single discovered vulnerability.

The distribution of new vulnerabilities is not uniform. While AI, bug bounties, and increased scrutiny contribute to the rising CVE volumes, the FIRST report also highlights the growing attention on open-source projects and the overall expansion of software worldwide. VulnCheck's analysis indicated that one-third of the KEVs exploited in the first half of 2026 targeted content management systems, with edge devices also featuring prominently, including vulnerabilities in products from major vendors like Check Point, Cisco, Fortinet, and Palo Alto Networks.

Despite the stable overall exploitation rate, there is evidence that newly targeted flaws are being exploited more rapidly. The median time from a CVE's publication to its exploitation dropped from 120 days in 2025 to 80 days in the first half of 2026, according to VulnCheck. This acceleration underscores the need for organizations to enhance their vulnerability management processes. FIRST recommends adopting "exploitability overlays" by closely monitoring CISA's KEV list and utilizing systems like the Exploit Prediction Scoring System (EPSS) to prioritize patching efforts.

As AI continues to evolve, experts are closely watching for a potential tipping point where attackers leverage AI to exploit a greater volume of vulnerabilities. Threat actors have a history of adopting new technologies that offer operational advantages, and AI is expected to be no exception. The coming period is anticipated to be defined by the race between AI-accelerated exploit generation and AI-accelerated patch generation, emphasizing the need for organizations to adapt quickly to these evolving dynamics.

Synthesized by Vypr AI