Google Report: AI Doubles Software Vulnerability Disclosures
Google's Threat Intelligence Group reports that the number of disclosed software vulnerabilities has doubled within months, rising from 5,045 in January 2026 to 10,740 by August 2026. The report attributes this surge to the increasing use of AI agents in security research, which uncover different types of flaws than traditional scanners. Notably, 50% of AI-found vulnerabilities lead to remote code execution, compared to 26% for conventionally discovered ones. The report also highlights a rise in exploitation of known 'N-day' vulnerabilities, from 28 in all of 2025 to 75 between January and August 2026, likely accelerated by AI-assisted exploit creation. Additionally, vulnerabilities in AI infrastructure itself are growing, with over 1,500 reports in 2026, focusing on orchestration frameworks like Langflow and inference servers such as vLLM and Ollama. The report advises prioritizing patches based on threat intelligence and recommends AI-powered code reviews for software vendors.
- •Vulnerability disclosures doubled from 5,045 in January 2026 to 10,740 in August 2026.
- •50% of AI-discovered vulnerabilities lead to remote code execution, vs. 26% for conventional methods.
- •Exploitation of N-day vulnerabilities rose from 28 in 2025 to 75 between January and August 2026.
