Google Threat Intelligence Group Reports Surge in Software Vulnerability Disclosures
A new report from Google LLC’s Google Threat Intelligence Group (GTIG) reveals a significant increase in software vulnerability disclosures, which have doubled from January to August 2026. This rise aligns with advances in artificial intelligence that have reshaped how vulnerabilities are identified and cataloged.
According to the report, the total number of vulnerabilities disclosed in August reached 10,740, more than double the 5,045 recorded in January. GTIG cautions that these figures might inflate the perceived threat level, particularly due to automated identifier assignments within open-source ecosystems. For example, vulnerabilities described with “Linux Kernel” accounted for approximately 5,000 disclosures this year, none of which resulted in zero-day exploits in the wild. Notably, high-risk disclosures surged by 167% over the same period, culminating in 350 such reports in August alone, including 128 that stemmed from Oracle Corp.’s quarterly patch release and Linux kernel network driver advisories.
Over the same time frame, GTIG reported that attackers successfully exploited 141 newly disclosed vulnerabilities, surpassing the total of 127 recorded throughout all of 2025. This translates to an exploitation rate of about one flaw for every 431 disclosures, highlighting that the reported numbers can fluctuate significantly based on individual vendor disclosure cycles or active attack campaigns.
The report further indicates that zero-day vulnerabilities, which are critical issues not yet patched by software vendors, have averaged 11 per month in 2026, compared to eight per month in 2025. The month of August alone saw a spike, with 22 zero-day exploits identified. Importantly, 62% of the exploited vulnerabilities this year were zero-days, while the majority of the increase in exploited vulnerabilities may be attributable to n-day vulnerabilities—those that are targeted after public disclosure and typically already patched.
GTIG posits that attackers could be leveraging large language models to streamline the process of identifying product versions and corresponding patches, enabling them to convert known vulnerabilities into effective exploits at a much quicker pace. Reports indicate that 75 high-risk vulnerabilities were exploited this year, a marked increase from just 28 in all of 2025.
Of the vulnerabilities identified by GTIG as likely stemming from AI initiatives, 58% were categorized as moderate risk. By contrast, vulnerabilities detected by human researchers and conventional scanners placed in the moderate category only about half as frequently, with a significant 69% being classified as low risk. GTIG suggests that researchers often target critical infrastructure and sensitive privilege boundaries, contributing to the disparity in findings.
The report underscores that while remote code execution vulnerabilities are found in only 26% of other disclosures, AI’s higher rate of detection may result from its ability to effectively identify complex issues such as memory corruption and logic bypasses in C and C++ code that traditional static analyzers might overlook.
GTIG currently considers confirmed attacks on AI-identified vulnerabilities as preliminary indicators of risk. One notable example is CVE-2026-1731, which allows unauthenticated attackers to execute OS commands in BeyondTrust Corp.’s Privileged Remote Access and Remote Support products. Discovered autonomously by a research agent from Hacktron AI Inc., this vulnerability was exploited by a threat cluster within days of its disclosure in February, leading to privilege escalation and data theft—specific payloads included SNOWLIGHT and SPARKRAT malware, as well as cryptocurrency miners.
In the final analysis, the report analyzes flaws in AI software, indicating that of the 2,076 instances GTIG has tracked since the beginning of 2025, more than 1,500 were reported this year. Notably, approximately half of these vulnerabilities were associated with agent orchestration frameworks such as Flowise and Langflow, which often integrate nodes capable of executing code, making them vulnerable to prompt injection or malicious workflow files. Vulnerabilities in inference and serving software like vLLM, Ollama, and LiteLLM also raised concerns, with GTIG identifying unauthenticated API endpoint vulnerabilities and server-side request forgery as significant threats.
Although GTIG has yet to observe any zero-day exploits specifically targeting AI infrastructure, a few disclosed flaws have surfaced in real-world exploitation scenarios. These include a command injection vulnerability in LiteLLM’s Model Context Protocol server preview endpoints and two in Langflow. Notably, a July incident documented by Sysdig Inc. highlighted an autonomous ransomware attack that exploited one of the older vulnerabilities found in Langflow.
Looking ahead, GTIG anticipates continued growth in both vulnerability discovery and exploitation rates, primarily focused on perimeter appliances and exposed enterprise services. The report advises organizations to prioritize threat intelligence over uncoordinated mass patching, suggesting that targeted defenses should be implemented at the enterprise edge. Software vendors are urged to adopt agentic AI for code reviews before production releases, with Google’s CodeMender recommended as a potential solution. If these practices gain traction, GTIG believes public disclosures may eventually decelerate.

