search

LEMON BLOG

AI Is Finding More Vulnerabilities, but VulnCheck Says Exploitation Is Not Rising at the Same Pace

Artificial intelligence is increasingly being used to search source code for security weaknesses, raising concerns that attackers could discover and weaponise vulnerabilities faster than defenders can patch them. The fear is understandable: an AI system can review enormous codebases, identify suspicious patterns and repeat that process far more quickly than a human researcher.

However, new data from vulnerability intelligence firm VulnCheck suggests the situation is more complicated than the warnings imply.

Its H1 2026 exploitation report found that vulnerabilities attributed to AI-assisted discovery were not more likely to be exploited in the wild than vulnerabilities found through conventional research. At the same time, the report shows that once a vulnerability becomes public, attackers are generally moving faster to take advantage of it.

The real concern may therefore be less about whether AI-found vulnerabilities are uniquely dangerous and more about how little time organisations now have between disclosure and active exploitation.

The Time Between Disclosure and Exploitation Is Shrinking

VulnCheck identified 495 vulnerabilities with confirmed exploitation activity during the first six months of 2026.

Approximately 23.4% showed signs of exploitation on or before the day their CVE details were published. That is lower than the figure recorded across 2025, when almost 29% of exploited vulnerabilities were already being attacked by the time public disclosure occurred.

At first glance, that sounds encouraging. A smaller proportion of vulnerabilities is reaching the public already weaponised.

The more concerning figure is what happens next.

VulnCheck calculated that the median period between CVE publication and confirmation as a known exploited vulnerability fell to 80 days during the first half of 2026. Across 2025, the equivalent figure was around 120 days.

In only six months, the median exploitation window shortened by roughly one-third.

That means fewer vulnerabilities may be under attack at the precise moment of disclosure, but attackers are catching up much more quickly once technical information becomes public.

Quarterly Patching Is Increasingly Difficult to Defend

Many organisations still operate around monthly or quarterly patch schedules. Updates may need to pass through testing, change-management approval and carefully planned maintenance windows before deployment.

That process makes sense for systems where an unstable patch could interrupt critical operations. However, a vulnerability that begins seeing active exploitation within weeks—or even days—cannot always wait for the next quarterly cycle.

CISA's Binding Operational Directive 26-04 reflects this change in urgency. It instructs relevant United States federal agencies to patch certain high-risk vulnerabilities within three days when exploitation is confirmed, automation is practical, the technical consequences are severe or the affected service is exposed to the public internet.

Private organisations are not necessarily bound by the same directive, but the underlying lesson still applies.

A patching process designed around the slower exploitation patterns of previous years may no longer provide enough protection. Security teams need a risk-based emergency pathway that allows critical fixes to bypass ordinary queues when exploitation is already happening.

More CVEs Do Not Automatically Mean More Exploited Vulnerabilities

The total volume of disclosed vulnerabilities continues to increase rapidly.

VulnCheck reported that CVE publication rose by 45% compared with the previous six-month period. Confirmed exploited vulnerabilities increased by only 10%.

As a result, the proportion of newly published CVEs that entered VulnCheck's known-exploited catalogue fell to 1.4% during the first half of 2026. That ratio had reached 2.7% during the second half of 2023.

Some newly published vulnerabilities may still be exploited months or years later, so the current percentage will not remain completely fixed. Nevertheless, the early data suggests exploitation is not expanding at the same rate as disclosure volume.

VulnCheck identified around 200 vulnerabilities that reached known-exploited status within 31 days of publication during the first half of 2026. That figure was broadly similar to 196 in 2024 and 194 in 2025.

In other words, the number of vulnerabilities experiencing rapid exploitation is relatively stable, even though the overall number of published vulnerabilities is increasing sharply.

That distinction is important for security teams struggling with alert overload. More CVEs do not necessarily mean every vulnerability deserves the same level of urgency.

AI-Discovered Vulnerabilities Are Not Showing a Higher Exploitation Rate

Warnings about AI-assisted vulnerability discovery have become increasingly serious.

Anthropic argued during the announcement of Project Glasswing that advanced AI systems could help attackers identify flaws capable of enabling system compromise, operational disruption and data theft before defenders have enough time to react.

VulnCheck attempted to measure whether those concerns were already visible in real-world exploitation data.

Across datasets from Anthropic and the Berkeley Vulnerability Research Initiative, VulnCheck tracked 1,061 vulnerabilities attributed to AI-assisted discovery.

Only 14—approximately 1.3%—had been confirmed as exploited in the wild. Four of those were reportedly observed against VulnCheck's own internet-facing monitoring systems.

That exploitation rate was broadly comparable with other vulnerabilities disclosed during the same period. It did not show that AI-discovered flaws were being weaponised more frequently or more quickly than vulnerabilities found through traditional methods.

The findings do not prove that AI poses no future risk. They indicate that the predicted acceleration has not yet clearly appeared in the available exploitation data.

AI May Be Increasing Discovery More Than Exploitation

AI tools appear capable of identifying more potential weaknesses across large software projects. That can benefit both sides of the security equation.

Attackers may use AI to find exploitable code paths, generate test cases or accelerate reconnaissance. Defenders can use the same technology to identify flaws earlier, notify vendors and deploy fixes before exploitation begins.

A larger number of findings therefore does not automatically translate into a larger number of successful attacks.

The outcome depends on who acts first.

When vendors respond quickly and organisations patch promptly, AI-assisted discovery may reduce risk by revealing vulnerabilities before malicious actors find them independently. When disclosure is poorly coordinated or patching is delayed, the same findings may instead give attackers a useful roadmap.

AI vulnerability discovery is best viewed as an accelerator. It speeds up the process, but it does not determine who benefits from that speed.

Anthropic's Vulnerability Ledger Raises Its Own Questions

Anthropic launched a public disclosure ledger in May 2026 containing 1,611 committed entries from more than 23,000 findings reportedly generated by Claude.

According to VulnCheck, the public ledger had not grown beyond its initial 1,611 entries by the time of its report, even though more than 150 findings had passed the disclosure deadline established under Anthropic's own coordinated-disclosure policy.

VulnCheck tracked 126 ledger findings that had received published CVE identifiers.

Only one—CVE-2026-26980—had been confirmed as exploited in the wild. VulnCheck also said it observed exploitation attempts against that vulnerability through its own monitoring network.

A single confirmed case is not enough to support broad claims that AI-discovered vulnerabilities are becoming disproportionately dangerous.

The stalled ledger also illustrates the gap between producing possible findings and completing the difficult work required to validate, coordinate and publish them responsibly.

Discovery is only the beginning. Every issue still needs human verification, vendor communication, severity assessment and remediation.

CMS Platforms Remain One of the Largest Attack Surfaces

While attention is focused on AI, VulnCheck's data points towards a more familiar and immediate problem: content management systems.

CMS-related vulnerabilities accounted for approximately one-third of all known exploited vulnerabilities added by VulnCheck during the period.

WordPress plugins made up much of that volume, although vulnerabilities affecting Drupal, Ghost and Kentico Xperience also appeared.

This should not be surprising. CMS platforms are widely exposed to the internet, often run third-party extensions and may be administered by marketing, communications or product teams rather than central security departments.

A website may receive regular content updates while its underlying plugins remain outdated for months.

Multi-site environments can make the problem worse. An organisation may operate dozens or hundreds of WordPress sites managed by different departments, agencies or external contractors. Security teams may not even have a complete list of installed plugins.

The Australian Signals Directorate recently warned of large-scale activity targeting website content management systems, aligning with VulnCheck's independent findings.

For organisations running public websites, CMS inventory and plugin patching should be treated as continuous security work—not a task reserved for quarterly maintenance.

Edge Devices Continue to Attract Attackers

Network-edge devices also remained a reliable source of newly exploited vulnerabilities.

VulnCheck recorded new entries affecting products from Cisco, Palo Alto Networks, Check Point, F5, Juniper, Fortinet, SonicWall, Ubiquiti, TOTOLINK, Tenda, D-Link, Netgear and Linksys.

Firewalls, VPN gateways, routers and remote-access appliances are attractive targets because they sit directly on the network perimeter. They are often publicly reachable and may provide attackers with access to internal environments when compromised.

These systems are also difficult to patch.

Firmware updates may require downtime, configuration backups, vendor support or full hardware replacement. Organisations often keep edge appliances for many years, especially when the devices appear to continue functioning normally.

CISA's Binding Operational Directive 26-02 focuses on the risks created by unsupported edge devices. Once a product reaches the end of its supported life, new vulnerabilities may no longer receive fixes even though the equipment remains exposed to the internet.

Attackers do not care whether an organisation's replacement budget is scheduled for next year. Unsupported hardware remains useful to them as long as it stays online.

AI Infrastructure Is Becoming a Direct Target

There is an important difference between vulnerabilities discovered using AI and vulnerabilities affecting AI platforms themselves.

VulnCheck found confirmed exploitation across 10 of the 28 AI-system vulnerabilities identified through its Canary monitoring network. These observations came from real internet-exposed systems rather than laboratory sandboxes.

Among the examples were CVE-2026-0769 and CVE-2026-5027 affecting LangFlow.

According to VulnCheck, attackers used the flaws to gain initial access, collect credentials linked to services such as OpenAI and Claude, deploy cryptocurrency miners and attempt to move laterally through affected environments.

Neither vulnerability had been added to CISA's Known Exploited Vulnerabilities catalogue at the time of the report.

This highlights an emerging security problem. AI development environments often contain highly valuable secrets, including API keys, cloud credentials, model-access tokens, database passwords and connections to internal systems.

An exposed AI workflow platform may provide attackers with more than access to a single application. It could become a route into the organisation's wider development and cloud infrastructure.

The Vulnerability Catalogue Will Always Lag Behind Some Attacks

CISA's KEV catalogue is widely used to prioritise patching, but no single list can capture every exploited vulnerability immediately.

VulnCheck's observations of LangFlow exploitation demonstrate that attacks may already be occurring before a vulnerability appears in CISA's catalogue.

That does not make the catalogue unreliable. It means organisations should not treat it as their only source of exploitation intelligence.

Security teams may need to combine CISA data with vendor advisories, independent researchers, threat-intelligence providers, internet-scanning organisations and sector-specific sources.

Waiting for one official list to confirm every threat can create unnecessary delays.

Who Is Identifying Exploitation First?

VulnCheck identified 79 separate sources that provided the first evidence of exploitation during the first half of 2026.

Patchstack led with 70 vulnerabilities, followed by CrowdSec with 64, Shadowserver with 57, VulnCheck with 37, Wordfence with 20 and CISA with 19.

The strong performance of Patchstack and Wordfence reflects the large number of actively exploited CMS and WordPress vulnerabilities.

Shadowserver's position highlights the value of large-scale internet monitoring. Its scanning and sinkhole data can reveal exploitation patterns before some vendors publicly acknowledge that attacks are underway.

VulnCheck's own CVE Numbering Authority assigned identifiers to 34 of the 495 known exploited vulnerabilities recorded during the period. The company describes this work as an attempt to publish identifiers and exploitation evidence before attackers gain too much of a lead.

For CISOs, the lesson is that vendor bulletins are only one part of the picture. In some cases, independent security organisations may report exploitation earlier than the affected vendor.

Patch Priorities Should Be Based on Exposure and Evidence

The findings support a more focused approach to vulnerability management.

Security teams are often overwhelmed by severity scores, scanner alerts and long lists of newly published CVEs. Attempting to patch everything immediately is unrealistic for most organisations.

Prioritisation should consider whether the vulnerability is being actively exploited, whether the affected system is exposed to the internet, whether exploitation can be automated and what level of access an attacker could gain.

A critical vulnerability affecting an isolated test system may represent less immediate danger than a medium-severity flaw being actively exploited against an internet-facing firewall.

Organisations should also pay special attention to systems that are difficult to inventory, including WordPress plugins, unmanaged websites, forgotten VPN gateways and experimental AI platforms.

The assets least visible to the security team are often the hardest to patch quickly.

AI-Generated Alerts Should Not Automatically Jump the Queue

The report also challenges the idea that vulnerabilities deserve higher priority merely because an AI system discovered them.

AI attribution does not currently appear to predict exploitation better than established risk factors such as public exposure, availability of exploit code, active attack evidence or the importance of the affected product.

Security teams should not ignore AI-discovered vulnerabilities. They should evaluate them using the same evidence-based criteria applied to other findings.

Automatically elevating every AI-generated report could produce even more alert fatigue, particularly as AI tools generate larger volumes of candidate vulnerabilities.

A finding that has been properly validated, affects a widely deployed product and enables severe compromise deserves attention. The fact that AI helped discover it is secondary.

The Data Does Not Eliminate Future AI Risk

VulnCheck's findings should not be interpreted as proof that AI-assisted vulnerability discovery will never benefit attackers.

The technology is evolving rapidly. AI agents may eventually become capable of discovering a flaw, developing a working exploit, identifying vulnerable internet-facing systems and launching attacks with limited human involvement.

The current data simply shows that this outcome is not yet clearly reflected in exploitation rates.

There may also be measurement limitations. Exploitation can occur without being detected, and many organisations do not publicly disclose attacks. Attribution of AI involvement in vulnerability discovery may also be incomplete.

The responsible conclusion is not that AI risk has been exaggerated entirely. It is that the strongest claims should be measured against real-world evidence rather than assumed from technical capability alone.

A Faster Exploitation Window Is the More Immediate Problem

For most organisations, the report's most practical warning is not about AI.

It is the reduction in the median time between disclosure and exploitation confirmation.

An 80-day median may still sound generous, but medians hide the vulnerabilities exploited within hours or days. Public proof-of-concept code, automated scanning and exposed services can compress the window dramatically.

Security teams need the ability to identify newly disclosed vulnerabilities affecting their environment quickly. That requires an accurate asset inventory, dependable vulnerability scanning and a process for emergency remediation.

Without knowing what systems and software are in use, even the best threat intelligence cannot tell an organisation what to patch.

Final Thoughts

VulnCheck's H1 2026 report presents a more balanced picture of AI-assisted vulnerability discovery.

AI is helping researchers identify more weaknesses, but the available data does not show that AI-discovered vulnerabilities are currently being exploited at a higher rate than other flaws. Only 14 of the 1,061 tracked AI-assisted findings had confirmed exploitation, broadly matching the rate across vulnerabilities disclosed during the same period.

That does not mean AI poses no danger. It means the predicted acceleration in exploitation has not yet been demonstrated clearly by the numbers.

Meanwhile, more traditional security problems continue to demand immediate attention. CMS platforms—particularly WordPress plugins—account for a large share of exploited vulnerabilities. Edge devices remain heavily targeted, and unsupported firewalls or VPN appliances can remain exposed long after vendors stop providing fixes.

AI infrastructure is also becoming a valuable target in its own right, with attackers exploiting workflow platforms to steal cloud and AI-service credentials, deploy miners and move deeper into networks.

The most urgent trend is the shrinking period between public disclosure and confirmed exploitation. Security programmes built around slow approval queues and quarterly patch cycles are becoming increasingly difficult to defend.

AI may reshape vulnerability discovery, but attackers are already exploiting familiar weaknesses in websites, edge appliances and exposed development systems. Organisations should prepare for future AI-driven threats without losing sight of the risks that are being actively exploited today.

Why Black and White Still Feels Powerful in a Worl...
Amazon Links Axios and Three Other NPM Supply-Chai...

Related Posts

 

Comments 0

Loading latest comments...
Saturday, 08 August 2026

Captcha Image

LEMON VIDEO CHANNELS

Step into a world where web design & development, gaming & retro gaming, and guitar covers & shredding collide! Whether you're looking for expert web development insights, nostalgic arcade action, or electrifying guitar solos, this is the place for you. Now also featuring content on TikTok, we’re bringing creativity, music, and tech straight to your screen. Subscribe and join the ride—because the future is bold, fun, and full of possibilities!

My TikTok Video Collection