GTIG: Vulnerability Trends in the AI Era and AI Infrastructure Attack Surfaces
1. Basic Information Article Title: Vulnerability Discovery and Exploitation Trends in the AI Era Publisher: Google Threat Intelligence Group Publication Date: 2026-09-30 Original Source: Google Threat Intelligenc
1. Basic Information
- Article Title: Vulnerability Discovery and Exploitation Trends in the AI Era
- Publisher: Google Threat Intelligence Group
- Publication Date: 2026-09-30
- Original Source: Google Threat Intelligence Group
- Related Resources: Mandiant vulnerability risk rating methodology, Mandiant Agentic Vulnerability Discovery Harness
- Importance: High (The analysis examines rising disclosure volumes, observed exploitation, the targeting of edge appliances, the risk profile of a likely AI-discovered sample, and 2,076 cumulative AI-related CVEs. It supports prioritizing remediation using threat intelligence.)
2. Executive Summary
GTIG analyzed data from January 2025 through August 2026. Monthly vulnerability disclosures increased from 5,045 in January 2026 to 10,740 in August. GTIG also reported an increase in the average number of vulnerabilities observed being exploited, from 10.5 per month in 2025 to 18 per month between January and August 2026.
GTIG observed exploitation of 0.23% of the vulnerabilities disclosed during JanuaryβAugust 2026. The findings support using threat intelligence to prioritize exposed edge appliances and AI middleware.
3. Scope and Methodology
- The analysis covers vulnerability disclosures and GTIG observations from January 1, 2025, through August 31, 2026. Sources include CISA advisories, MITRE records, vendor security advisories, and AI research program records.
Evaluation Design
- The baseline monitoring period spans 20 months. Risk classifications use GTIG Vulnerability Risk Ratings, not CVSS severity scores.
- Because standardized metadata identifying AI involvement in vulnerability discovery is unavailable, GTIG used a subset it identified as likely AI-discovered for comparison.
- The separate AI-related CVE count classifies vulnerabilities by the affected technology. It does not imply that those vulnerabilities were discovered by AI.
4. Key Findings
- Monthly vulnerability disclosures increased from 5,045 in January 2026 to 10,740 in August. The reported monthly average number of exploited vulnerabilities increased from 10.5 in 2025 to 18 during JanuaryβAugust 2026.
- GTIG observed exploitation of 141 distinct vulnerabilities disclosed during JanuaryβAugust 2026, representing 0.23% of disclosures in that period. Of those 141 vulnerabilities, 62% were exploited as zero-days.
- Fourteen percent of the 141 vulnerabilities affected edge or security appliances. More than 65% of that subset received High or Critical GTIG risk ratings.
- In the JanuaryβAugust 2026 sample identified as likely AI-discovered, GTIG classified 39% as Low risk, 58% as Medium, and 4% as High. These percentages are reproduced at the source's reported precision and do not sum to 100%. Fifty percent of the sample was classified as having remote code execution (RCE) as an exploitation consequence, compared with 26% of the group not identified as AI-discovered. These figures are not RCE attack success rates.
- GTIG tracked 2,076 cumulative AI-related CVE disclosures during January 2025βAugust 2026. For the separate JanuaryβAugust 2026 breakdown, the eight architectural categories total 1,584. AI orchestration and agent frameworks account for 782, approximately half of that total, while inference and serving infrastructure account for 212.
5. Interpretation and Limitations
- Automated CVE assignment policies used by CVE Numbering Authorities (CNAs), including in the Linux kernel ecosystem, can increase disclosure counts without a corresponding increase in observed exploitation.
- Identifying AI involvement requires manual heuristics. Public data undercount vulnerabilities fixed without public disclosure and findings still under disclosure embargoes. The comparison group not identified as AI-discovered may also contain unreported AI-assisted discoveries.
- An absence of observed exploitation does not establish that exploitation has not occurred.
- Correlation alone does not establish that AI caused the increase in vulnerability disclosures.
6. Facts / Inference / Hypothesis
Facts
- Monthly vulnerability disclosures increased from 5,045 in January 2026 to 10,477 in July and 10,740 in August.
- GTIG reported an increase in the monthly average number of exploited vulnerabilities from 10.5 in 2025 to 18 during JanuaryβAugust 2026. It observed exploitation of 141 vulnerabilities disclosed during the latter period, corresponding to 0.23% of disclosures, described in the source as roughly 1 in 431. This is an observation within GTIG's dataset, not a global exploitation rate or a probability of future exploitation.
- The reported monthly average number of vulnerabilities exploited as zero-days increased from 8 in 2025 to 11 during JanuaryβAugust 2026. Zero-days accounted for 62% of the vulnerabilities observed being exploited during the latter period.
- Fourteen percent of the 141 vulnerabilities disclosed and observed being exploited during JanuaryβAugust 2026 affected edge or security appliances. More than 65% of that subset received High or Critical GTIG risk ratings.
- Fifty percent of the likely AI-discovered sample was classified as having RCE as an exploitation consequence, compared with 26% of the group not identified as AI-discovered. The classification relies on heuristics because standardized metadata are unavailable. The comparison group is not confirmed to exclude all AI-assisted discoveries, and the percentages do not measure exploitation success.
- GTIG tracked 2,076 cumulative AI-related CVE disclosures during January 2025βAugust 2026. Summing the eight rows in its JanuaryβAugust 2026 architectural breakdown yields 1,584, including 782 in AI orchestration and agent frameworks, approximately half of that total. Inference and serving infrastructure account for 212 during the same period; GTIG reports that 24% of those vulnerabilities involve unauthenticated API endpoints or server-side request forgery (SSRF).
Inference
- Prioritizing patches solely by disclosure volume may overlook exploited edge vulnerabilities, higher-risk flaws, and evidence from threat actor campaigns.
- The higher RCE proportion in the likely AI-discovered sample may partly reflect research programs selecting critical code paths for analysis. This comparison alone does not isolate the contribution of agent capabilities from the effects of target selection.
Hypothesis
No additional hypotheses. Unconfirmed items are listed in Section 7, "Unknowns and Further Investigation."
7. Unknowns and Further Investigation
- The true proportion of vulnerability discoveries involving AI across the full population, given the lack of standardized attribution metadata.
- The number of AI-discovered vulnerabilities fixed without public announcements in cloud and SaaS environments.
- Direct causal evidence isolating the effect of AI assistance on the time required to weaponize n-day vulnerabilities.
8. Implications for Defenders
Vulnerability management should combine evidence of exploitation, external exposure, an asset's role at the network edge or in identity infrastructure, privileges, and remediation feasibility when setting priorities. AI gateways, orchestrators, and inference servers handle or provide access to API keys, prompts, models, and cloud credentials. Because traditional web application inventories can overlook these components, include them explicitly in asset inventories and attack surface monitoring.
Deployment and Operational Guidance
- Prioritize edge and security appliances and management APIs that allow administrative operations without authentication.
- Inventory AI orchestrators, gateways, and inference servers. Review external exposure, SSRF risks, dynamic code execution nodes, and access to secrets.
Required Evidence
- Link the asset, version, exposure status, exploitation evidence, responsible owner, patch or mitigation status, credential rotation, and post-update verification in a single record.
9. Summary by Role
- For SOCs: Combine CISA KEV entries, vendor exploitation reports, and GTIG risk ratings with asset exposure information to prioritize threat hunting on edge appliances and AI middleware.
- For Administrators: Inventory publicly accessible management interfaces and AI gateways. Prioritize remediation, isolation, and credential rotation according to risk.
- For Users: No direct technical action is required, but follow update guidance for the AI services and security appliances you use.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes β full credit and traffic to the original publisher.