Skip to content

Product1 publisher3 min readPublished

Attackers exploited one in 431 new vulnerabilities this year by Google's count

Google's Threat Intelligence Group counted 141 flaws exploited in the wild from January to August, while monthly disclosures doubled to 10,740. Patch teams do better sorting by that exploited set than by the total, though attackers now reach some public flaws within days.

The Product Desk · Product desk

Illustration accompanying Attackers exploited one in 431 new vulnerabilities this year by Google's count

What happened

  • Flaws with Linux Kernel in their descriptions made up about 5,000 records this year without producing a single zero-day exploited in the wild.
  • Exploited high-risk flaws on GTIG's scale reached 75 between January and August, up from 28 in all of 2025.
  • GTIG attributes most of the growth in exploitation to n-days, flaws attackers go after once they are public and usually already patched.
  • GTIG has tracked 2,076 disclosures in AI software since the start of 2025, about half in agent orchestration frameworks such as Flowise and Langflow.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • decision A team staffing to the raw feed plans for tens of thousands of records, while triage on exploitation in the wild cuts the urgent list to about one flaw in 431.
  • contradiction GTIG says automated identifiers inflate the total, yet exploited high-risk flaws arrive about four times as often per month as in 2025, so writing the growth off as noise underweights its fastest part.
  • constraint Waiting for exploitation evidence leaves only days to patch once it arrives, so high-risk flaws still awaiting a first attack need a fast lane of their own.
  • exposure Self-hosted AI tools sit outside the exploitation signal for now because GTIG has seen no zero-day attacks on AI infrastructure, so an exploitation-gated queue will not flag them.

A patch team reading the intake count this year is reading a number its own source discounts. Google's Threat Intelligence Group (GTIG) says raw disclosure totals overstate the threat because automated identifier assignment in open-source ecosystems inflates them [2].

The version teams tell themselves is that twice the intake means twice the exposure. What attackers actually did was exploit about one newly disclosed flaw in 431 [6]. Applied to the 141 exploited flaws, that ratio implies roughly 60,800 disclosures from January to August [1]. The high-risk tier is concentrated in a few sources too. Of August's 350 high-risk disclosures, 128, or about 37%, came from Oracle's quarterly patch release and Linux kernel network driver advisories [4][4]. The report says one vendor's disclosure cycle or one busy campaign can move the monthly figures [7].

The high-risk end of the exploited set is growing fastest. Spread over eight months, 141 exploited flaws is about 17.6 a month, against about 10.6 a month in 2025, a rise of about two-thirds [5][2]. Exploited high-risk flaws run at about 9.4 a month against 2.3, roughly four times last year's rate [3]. Zero-days averaged 11 a month against eight in 2025, and August reached 22 [8]. They were still 62% of the exploited set [9]. The report says attackers may be using large language models to compare product versions and patches so they can turn known flaws into working exploits quickly [11].

GTIG calls the risk from AI-found flaws "not purely theoretical" [18]. Its example, CVE-2026-1731, lets an unauthenticated attacker inject operating system commands into BeyondTrust's Privileged Remote Access and Remote Support products [16]. Attackers who used it escalated privileges, stole data and dropped SNOWLIGHT and SPARKRAT malware plus cryptocurrency miners [17]. Half the flaws AI agents turn up allow remote code execution, against 26% of other disclosures [14]. GTIG says that likely reflects how well agents pick out memory corruption and logic bypasses deep in C and C++ code that static analyzers miss [14]. Among likely AI discoveries, 58% land in GTIG's moderate risk tier, about twice the rate for bugs found by people and conventional scanners [15]. GTIG thinks researchers aiming their agents at critical infrastructure on purpose explains much of that gap [15].

Teams running their own AI tooling have a separate list. Visual workflow builders such as Flowise and Langflow often include nodes that execute code, and attackers can reach them with prompt injection or a crafted workflow file [22]. In serving software such as vLLM, Ollama and LiteLLM, GTIG traced nearly a quarter of 212 disclosures to unauthenticated API endpoints or server-side request forgery [20].

I'd sort the queue on two questions: has the flaw been exploited in the wild, and is it high-risk or a remote code execution bug. Exploited and high-risk goes first, within days. The BeyondTrust flaw drew six threat clusters inside a week of disclosure [5]. Exploited but lower-risk gets a scheduled window. High-risk but unexploited is the hard box, because n-days are where exploitation is growing [10]. Internet-facing items in that box, agent-found RCE bugs above all, belong in the fast lane too. Unexploited, low-risk records go through the normal patch cycle. The tradeoff is that an exploitation gate waits for attackers to supply the evidence, and for high-risk flaws they are supplying it about four times as often per month as in 2025 [3].

What to watch

  • Whether September's zero-day count stays near August's 22 or falls back into the eight-to-12 range of most earlier months.
  • Whether vulnerability databases adopt a standard tag for AI-assisted discovery; GTIG says the lack of one means public data undercounts AI-found flaws.
  • The first confirmed zero-day exploitation of AI infrastructure such as vLLM, Ollama or LiteLLM, which GTIG has not yet observed.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories