Skip to content

Security4 publishers2 min readPublished

Google traces most of 2026's exploitation growth to fast n-day weaponization

Google's threat intelligence group counts 18 exploited flaws a month in 2026, up from 10.5 in 2025, while zero-days rose only from eight to 11. GTIG attributes most of the added attacks to fast weaponization of disclosed n-days, so the exposure sits in the days after a patch ships.

The Watch · Security desk

Illustration accompanying Google traces most of 2026's exploitation growth to fast n-day weaponization

What happened

  • Half of the vulnerabilities GTIG judged likely AI-discovered led to remote code execution, against 26% of other CVEs.
  • Total vulnerability disclosures doubled from 5,045 in January 2026 to 10,477 in July, then reached 10,740 in August.
  • Zero-day exploitation spiked to 22 in August alone.
  • Edge and security appliances made up 14% of exploited vulnerabilities in 2026, and over 65% of those flaws were rated high or critical.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • decision Patch targets set by zero-day volume track the slower-growing category; n-day weaponization, which supplied most of the increase, now sets the deadline.
  • contradiction August's 22 zero-days, double the 2026 monthly average, cut against a purely n-day explanation, and one month cannot show whether the spike holds.
  • constraint Google ties the RCE skew partly to where researchers aim their agents, so the 50% rate cannot be read as a forecast for AI-found bugs at large.
  • cost NetScaler owners pay for a compromise hunt before the upgrade, because Mandiant says patching alone may not remove an intruder already inside.

Taking zero-days out of GTIG's monthly averages leaves 2.5 exploited flaws a month in 2025 and 7 in 2026 [1]. Those non-zero-days supplied 4.5 of the 7.5 extra flaws exploited each month, or 60% of the rise [2]. Zero-days are still the larger group, 11 of the 18 a month, about 61% [7]. GTIG suggested the growth came mostly from rapid weaponization of n-days, possibly aided by AI tools that analyze patches and proof-of-concept code [5].

CVE-2026-1731 is an unauthenticated command injection flaw in BeyondTrust Privileged Remote Access and Remote Support, found autonomously by Hacktron AI [10]. Six threat clusters were exploiting it within seven days of disclosure [3]. A deployment still unpatched on day five was already inside the first cluster's window [4]. Google called confirmed exploitation of AI-discovered flaws an early indicator, not yet an established trend [9].

On GTIG's own risk ratings, which are not CVSS scores, medium-risk flaws were 58% of likely AI-discovered vulnerabilities from January to August, against 28% of the rest [6]. Low-risk flaws were 39% and 69% [6]. That leaves the same 3% of each group outside those two tiers, so the shift in the AI-found set is from low to medium [6]. Google said the distribution likely reflects, in large part, how researchers deploy autonomous agents, aiming them at critical infrastructure instead of running broad scans [7]. It also said public data undercounts AI-discovered vulnerabilities [8]. The published figures do not say how much of the doubling in total disclosures came from AI-assisted discovery [2].

Bugs in AI software itself are a small part of the exploitation count so far. GTIG tracked more than 1,500 AI-related vulnerabilities disclosed in 2026 [12]. Agent orchestration frameworks accounted for 782 and inference and serving infrastructure for 212, nearly a quarter of those involving unauthenticated APIs or server-side request forgery [12]. Only a handful have been confirmed exploited, and GTIG has yet to see zero-day exploitation of AI infrastructure [13].

The research followed Citrix's fixes for two exploited NetScaler zero-days. GTIG and Mandiant have tracked one of them in active attacks [15]. "Given the active exploitation, NetScaler customers should prioritize examining their systems for compromise before upgrading/patching," Charles Carmakal, CTO at Mandiant, wrote on LinkedIn on September 27 [16]. "Patching alone may not eradicate the threat actor from your environment," he wrote [16].

What to watch

  • Whether GTIG's September zero-day count stays near August's 22 or falls back toward the 11-a-month average.
  • First confirmed zero-day exploitation of AI orchestration or inference infrastructure, where GTIG has so far seen only a handful of exploited flaws.
  • Direct evidence that attackers use AI patch-analysis tools to shorten n-day timelines, a link GTIG has so far only suggested.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories