AI is finding twice as many software flaws. Almost none get exploited.

AI-discovered Vulnerabilities: Explained

AI is finding twice as many software flaws. Almost none get exploited.

Key Findings

  • The US vulnerability database logged 45,207 flaws in seven months (January to 27 July 2026), already approaching the total for all of 2025.
  • This rate is significantly higher than the historical average, but exploitation rates remain low.
  • Only 1.3% of AI-discovered vulnerabilities were exploited, matching the overall exploitation rate.
  • Despite concerns about AI-driven attacks, practical evidence of exploitation has been lacking.

The Picture from VulnCheck

Vulnerability intelligence firm VulnCheck analyzed exploited vulnerabilities in the first half of 2026 and found:

  • 495 exploited vulnerabilities in total.
  • Among vulnerabilities attributed to AI-assisted discovery, only 14 (1.3%) were confirmed as exploited.

Comparison with Historical Data

  • The share of CVEs (Common Vulnerabilities and Exposures) that are eventually exploited has declined from a peak of 2.7% in late 2023 to the current rate of 1.4%.
  • While the number of published CVEs increased by 45%, the number of exploitable ones grew only by 10%.

Anthropic's Glasswing Project

Anthropic, with its AI model Claude, claimed to have identified 23,019 findings in May. However, VulnCheck's check revealed:

  • The public disclosure ledger from Anthropic stopped at 1,611 entries.
  • Only one of these has been confirmed as exploited in the wild.
  • Despite promises, no new disclosures or updates have been published by Anthropic since May.