Leadership1 publisher3 min readPublished
Monthly vulnerability disclosures more than double since start of 2026, GTIG finds
Google Threat Intelligence Group counted 10,740 vulnerability disclosures in August, more than double the monthly figure at the start of 2026. Exploitation is rising more slowly, so the first call on any budget reopened this quarter is triage capacity.
The Board Room · Leadership desk

What happened
- High-risk disclosures rose from 131 in January to 350 in August, a 167% increase, though they remain about 3% of all disclosed flaws.
- GTIG researchers said only 0.23% of vulnerabilities disclosed in 2026, roughly one in 431, have been seen in active exploitation.
- Public data undercounts AI-found flaws, GTIG said, because cloud and SaaS providers often fix them in production without requesting CVE IDs.
Compiled by The Board RoomSomething wrong?How this is made
Why it matters
- decision A team reopening its January budget has to choose between patch staff added in step with disclosure counts and triage that isolates the roughly one-in-431 flaws seen exploited.
- exposure Because CVE numbers go mostly to on-premises and third-party software, the counted surge falls on systems customers patch themselves while cloud fixes happen out of sight.
- contradiction GTIG credits AI with changing discovery yet ties the high-risk jump to vendor breadth and clustered disclosure cycles, so part of the surge may be calendar spikes, a weak basis for permanent hires.
- cost If the trends GTIG expects to continue do hold, headcount added to meet this quarter's queue becomes a fixed cost carried into next year's plan.
A security budget pays for two kinds of work: clearing the queue of disclosed flaws, and closing the few that attackers use. GTIG's figures show the first growing faster, with monthly disclosures more than doubling since January [1]. Exploited vulnerabilities rose about 71% when the 2026 monthly average is set against 2025's [1]. Zero-day exploitation went from eight cases a month to 11 [4], a rise of about 38% [2].
These growth rates do not share a baseline. The disclosure figure runs from the start of the year to August [1], and the high-risk figure from January to August [6]. Exploitation compares a 2025 monthly average with a 2026 year-to-date one [2], so any gap between volume and risk is approximate. The exploited share is small either way. The researchers said "only 0.23% of all disclosed vulnerabilities in 2026 (roughly one in 431) were ever observed in active exploitation" [8].
Steve Povolny, vice president of AI strategy and security research at Exabeam [11], drew a conclusion from the slow zero-day line. "This leads to one of two conclusions: first, AI models are very good at uncovering known (N-day) vulnerabilities but not mature enough to discover widespread zero-day vulnerabilities of significance," he said [12]. His other option was that AI-driven zero-day discovery is happening out of view. "Given the amount of security researchers focused on leveraging AI for zero-day discovery, I think the latter is less likely," he said [13]. If he is right, the growth is in known flaws, the ordinary work of a patch programme. GTIG also reported fewer low-risk finds and more moderate-risk and remote code execution flaws [5].
Whether January budgets are now too small depends on how a team patches. A team that planned against a monthly count below 5,370 [3] and works every disclosure now faces more than twice that queue [1]. A team that patches on evidence of exploitation faces a rise of about 71% from a base of tens a month [1] [8]. The GTIG report does not cover spending or headcount, so the budget case rests on workload.
The strongest caution comes from GTIG itself. Monthly exploitation counts "can more easily be influenced by other factors such as vendor disclosure cycles and threat actor campaign spikes," the researchers said [9]. They put the high-risk rise down to a widening pool of affected vendors and concentrated vendor disclosure cycles [7]. High-risk disclosures still rose 167% [6], so the extra work is real. The trade-off this quarter is between surge capacity, in contract hours or automation, and permanent hires. In my view, load that arrives on a vendor's release calendar favours the first, because staff hired for an August peak are a fixed cost in next year's plan.
Public counts also miss part of what AI finds. GTIG said cloud and SaaS providers routinely fix AI-surfaced flaws in production without requesting CVE IDs, and that CVE assignments are typically reserved for on-premises or third-party software [10]. The counted growth lands on the estate a customer patches itself [10].
GTIG researchers said they expect the disclosure and exploitation trends to continue in the short to medium term [3]. If they hold, a one-time top-up approved this quarter will be measured next quarter against a count that is still rising.
What to watch
- GTIG's monthly counts for September onward, to show whether August's 10,740 is a trend or a vendor disclosure-cycle spike.
- Whether zero-day exploitation stays near 11 a month; a jump would undercut Povolny's view that AI mostly finds known flaws.
- Any standard metadata for flagging AI-discovered vulnerabilities, so public counts show how much cloud and SaaS fixes now leave out.