Google Research: AI-Discovered Bugs Twice as Likely to Enable Remote Takeover
New research from Google Threat Intelligence Group (GTIG) shows that vulnerabilities likely discovered using AI tools are disproportionately dangerous. Half of these AI-found flaws resulted in remote code execution, compared to just 26% of other vulnerabilities. Overall vulnerability disclosures have also doubled in 2026, from around 5,000 in January to over 10,700 by August, while the average number of exploited vulnerabilities per month has climbed from 10.5 in 2025 to 18 so far this year.
Interestingly, zero-day exploitation only rose slightly, suggesting most of the increase comes from attackers rapidly weaponising known vulnerabilities (so-called n-days) shortly after patches are released, potentially with AI assistance analysing patch details and proof-of-concept code. Google noted that AI-discovered vulnerabilities also skew toward medium and low severity ratings, likely because researchers point AI tools at critical infrastructure rather than running broad, indiscriminate scans.
One real-world example cited is CVE-2026-1731, a command injection flaw in BeyondTrust remote access software that was discovered autonomously by an AI tool. Within four days of disclosure, one threat group had already exploited it, with five more following within a week. GTIG also tracked over 1,500 AI-related vulnerabilities in 2026, mostly in agent orchestration frameworks and AI infrastructure, though confirmed exploitation of these remains limited for now.