AI-discovered Vulnerabilities: Explained
AI is finding twice as many software flaws. Almost none get exploited.
Key Findings
- The US vulnerability database logged 45,207 flaws in seven months (January to 27 July 2026), already approaching the total for all of 2025.
- This rate is significantly higher than the historical average, but exploitation rates remain low.
- Only 1.3% of AI-discovered vulnerabilities were exploited, matching the overall exploitation rate.
- Despite concerns about AI-driven attacks, practical evidence of exploitation has been lacking.
The Picture from VulnCheck
Vulnerability intelligence firm VulnCheck analyzed exploited vulnerabilities in the first half of 2026 and found:
- 495 exploited vulnerabilities in total.
- Among vulnerabilities attributed to AI-assisted discovery, only 14 (1.3%) were confirmed as exploited.
Comparison with Historical Data
- The share of CVEs (Common Vulnerabilities and Exposures) that are eventually exploited has declined from a peak of 2.7% in late 2023 to the current rate of 1.4%.
- While the number of published CVEs increased by 45%, the number of exploitable ones grew only by 10%.
Anthropic’s Glasswing Project
Anthropic, with its AI model Claude, claimed to have identified 23,019 findings in May. However, VulnCheck‘s check revealed:
- The public disclosure ledger from Anthropic stopped at 1,611 entries.
- Only one of these has been confirmed as exploited in the wild.
- Despite promises, no new disclosures or updates have been published by Anthropic since May.