All posts

AI-found vulnerabilities see same 1.3% exploit rate as human finds

Manaal KhanAugust 18, 2026 at 10:16 PM4 min read
AI-found vulnerabilities see same 1.3% exploit rate as human finds

AI systems are flooding security teams with vulnerability reports, but attackers are ignoring almost all of them. VulnCheck's analysis of the first half of 2026 found that only 14 of 1,061 AI-discovered security flaws were actually exploited in the wild. That 1.3% rate matches the overall exploitation rate for all vulnerabilities, AI-found or not.

AI-found vulnerabilities see same 1.3% exploit rate as human finds
Source: The Decoder

The data punctures a quiet assumption in enterprise security: that AI-assisted discovery would surface a higher grade of exploitable bugs. It does not. The sheer volume of findings, Patrick Garrity of VulnCheck notes, tells defenders almost nothing about actual risk.

Advertisements

Anthropic's 23,000 findings, one confirmed attack

This Startup’s AI Found Critical Vulnerabilities That Anthropic’s Mythos Missed

Anthropic's Project Glasswing offers the starkest example. The initiative produced more than 23,000 findings, which led to 126 published CVE entries. Exactly one of those saw a confirmed attack. That conversion rate, from discovery to weaponization, suggests AI excels at breadth but offers no special insight into what attackers will actually pursue.

Security teams already struggle with alert fatigue. Adding thousands of low-signal findings from AI tools risks making the problem worse, not better.

Exploits are landing faster

The more urgent signal in VulnCheck's data is speed. Half of all exploited flaws now see their first confirmed attack within 80 days of disclosure, down from 120 days in the prior year. About 200 were attacked within a month. Roughly 23% were exploited on or before the day of disclosure.

VulnCheck chart showing time from vulnerability disclosure to first confirmed exploit in H1 2026, with 23% exploited on disclosure day and median dropping from 120 to 80 days
Image (Source: The Decoder)

That compression matters more than volume. A security team that takes 90 days to patch is now behind the median attacker timeline. The old 120-day window gave teams a margin. That margin is gone.

Where the attacks concentrate

Website content management systems account for a third of all exploited cases. Garrity also flags AI products themselves as an emerging attack surface, including model-building tools and agent interfaces.

That second category will concern any team shipping AI features. The tooling you use to build models may itself become the vector. It is an inversion: the security tool becomes the security problem.

80 days
New median time from vulnerability disclosure to first confirmed exploit in H1 2026, down from 120 days the year before

What this means for security prioritization

The data argues against treating AI-discovered vulnerabilities as a special class. They are not more likely to be exploited. Prioritization should still track observed attacker behavior, not discovery method.

It also argues for speed over volume. Patching 80% of findings in 120 days is now a losing posture. The teams that will matter are those that can triage and ship fixes inside 30 days for anything remotely plausible.

ℹ️

Logicity's Take

The headline story is reassuring: AI is not handing attackers better ammunition. The buried story is not. Exploit timelines are compressing faster than most patch cycles. For product teams, the takeaway is operational, not strategic. Your vulnerability backlog is not a list to work through. It is a race, and the finish line moved 40 days closer this year.

Also Read
Researchers tricked Copilot into revealing its own flaws

Related coverage on AI systems as security attack surfaces

ℹ️

Need Help Implementing This?

For teams building AI-powered security workflows or tightening patch cycles, reach out to discuss how to operationalize these findings in your stack.

Source: The Decoder / Thomas Joos

M

Manaal Khan

Tech & Innovation Writer

Produced with AI assistance and reviewed by the Logicity editorial team. Learn more in our Editorial Policy.