// 3 ZERO-DAY · 7 CVE · 8 EXPLOIT IN THE LAST 24H→
Google Threat Intelligence Group data shows AI-discovered vulnerabilities are twice as likely to be exploited for remote code execution. The patching window has collapsed to four days as attackers use LLMs to weaponize n-days at speed.

The Google Threat Intelligence Group published an analysis on October 1, 2026 that upends the offensive security paradigm: vulnerabilities discovered by AI systems are not merely more numerous and benign — they are the ones attackers actively pursue. The key figure is that 50% of these flaws lead to Remote Code Execution, versus 26% for those found by traditional methods. The time compression is equally severe: CVE-2026-1731, discovered by the Hacktron AI agent, went from disclosure to active exploitation in four days.

Key Takeaways
  • 50% of AI-discovered vulnerabilities lead to RCE, compared to 26% of others, per GTIG.
  • CVE-2026-1731 was exploited by a threat cluster within 4 days of disclosure; five clusters were active by day 7.
  • Attackers use LLMs to analyze patches and PoCs and rapidly weaponize n-days, according to GTIG.
  • Monthly disclosures doubled from 5,045 in January 2026 to 10,740 in August, while GTIG High Risk exploits rose from 28 to 75.

The Metric That Changes Triage: RCE at Twice the Rate

The quantitative distinction is sharp and explains the strategic relevance of the phenomenon. According to GTIG, 50% of vulnerabilities tagged as likely AI-discovered lead to RCE, versus 26% for those found by other methods. The proportion of low-risk flaws flips: 39% for AI-discovered versus 69% for non-AI. Medium-risk vulnerabilities, meanwhile, rise to 58% versus 28%.

GTIG attributes this distribution to the scope of automated research programs, which target exposed infrastructure and privilege boundaries. It is not that AI finds more vulnerabilities in absolute terms; it finds them in the zones where an exploit has the highest impact. The global rate of vulnerabilities exploited in-the-wild remains very low, roughly 0.23% in 2026, but the absolute count is growing: 141 exploits observed from January through August 2026, versus 127 for all of 2025.

Four Days: The Patching Window Is Shut

Chronologically, the most emblematic case is CVE-2026-1731. Discovered by the Hacktron AI agent, it drew exploitation from a threat cluster within 4 days of public disclosure. By day 7, five clusters were active. Attackers achieved privilege escalation, exfiltrated data, and deployed SNOWLIGHT, SPARKRAT, and cryptominer payloads.

The CVE-2026-1731 pattern is not isolated. CERT-EU documented exploitation of CVE-2026-88771 in NetScaler appliances within 24 hours of the September 27, 2026 patch, with PHP web shell installation for persistence. CISA confirmed active global exploitation of CVE-2026-88771 and CVE-2026-88772 within 3 days of the patch. No source links these NetScaler cases to AI discovery; they serve to demonstrate that the offensive cycle has compressed regardless of vulnerability provenance, and that AI-discovered flaws enter this accelerator already in its most dangerous phase.

"The vulnerabilities AI finds are the ones attackers want" — GTIG analysis title, Help Net Security

Attackers Use AI to Weaponize, Not Just to Discover

A distinctive element of the GTIG report is the recognition of an offensive feedback loop. Attackers use LLMs and AI tools to analyze patches, disclosure announcements, and proof-of-concept code, accelerating the weaponization of n-days. GTIG phrases this observation with linguistic caution: "it is possible that attackers find it more accessible or efficient to use LLMs and AI tools." The formulation is prudent, but the chronological data point — 4 days for CVE-2026-1731 — supports the reading that the offensive pipeline has compressed.

The quantitative context is alarming: monthly disclosures doubled from 5,045 in January 2026 to 10,740 in August. Zero-days detected by GTIG rose from 8 per month in 2025 to 11 in 2026. Exploits classified as High Risk by GTIG jumped from 28 to 75. The volume growth overlaps with a qualitative selection: AI-discovered vulnerabilities strike high-impact areas, while attackers automate the next phase.

The AI Attack Surface: Orchestration and Automation

GTIG's figure for AI-related software is 2,076 vulnerabilities from January 2025 through August 2026, over 1,500 in 2026 alone. Half hit agent orchestration frameworks such as Flowise and Langflow. These tools, used to build autonomous agent pipelines, introduce an attack surface that amplifies damage: compromising the orchestrator means compromising the chain of tools the agent can invoke.

Testimony from Gal Nagli, head of offensive security at Wiz, published in Calcalist, corroborates this reading. Nagli describes a radical transition: "Before I hoped to find a vulnerability manually overnight. Today the AI tells me: I've compromised the organization, here are all the secrets." Wiz scans roughly 200 environments per week with its Red Agent; 30% of clients, including 65% of the Fortune 100, accept proactive automated attacks. Nagli adds: "Today you can build an agent whose capabilities exceed those of the best researchers in the world."

This evidence does not prove attackers use AI to discover zero-days — GTIG's claim concerns the weaponization of n-days, not discovery — but it confirms that offensive automation has reached an efficacy threshold that alters defensive equilibria. The asymmetry is no longer just one of scale, but of the speed of closing the discovery-to-exploit loop.

What to Do Now

Defensive logic must update on three axes. Triage must prioritize AI-discovered vulnerabilities and those with public PoCs, treating the 4-7 day window as a real operational limit, not a theoretical one. Threat intelligence must integrate GTIG and CISA KEV feeds to identify active threat clusters on specific CVEs. Asset inventory must explicitly map agent orchestration frameworks, which now constitute half the exposed AI-related surface.

Internally, organizations deploying AI tools must assess whether the teams managing these systems — often non-technical figures designated "model champions" — possess the skills to recognize an insecure configuration or service exposure. Nagli's testimony suggests offensive automation already exceeds human capacity for manual review; defense requires automated scanning tools and integration with vendors providing these services.

FAQ

Why do AI-discovered vulnerabilities have a higher probability of RCE?
GTIG observes that automated research programs target exposed infrastructure and privilege boundaries, areas where an exploit typically has greater impact. The correlation may be selective — AI searches where damage is more likely — rather than causal.

Do attackers also use AI to discover zero-days?
The documented GTIG claim concerns the weaponization of n-days via automated analysis of patches and PoCs, not the discovery of zero-days with AI. The dossier contains no evidence of attacks using AI to find previously unknown vulnerabilities.

Does the 4-day cycle apply to all vulnerabilities?
No. The 4 days refer to CVE-2026-1731, an AI-discovered vulnerability with specific technical characteristics. The NetScaler cases (24 hours, 3 days) show rapid exploitation but are not linked to AI discovery. GTIG's general figure is that only 0.23% of 2026 CVEs were observed exploited.

Asymmetric pressure is the theme emerging from the data. Defenders built patching pipelines on 30-90 day windows; attackers, armed with AI to analyze patches and PoCs, operate on 4-7 days. This is not a volume problem — 99.77% of 2026 vulnerabilities were not exploited — but a target quality problem. The vulnerabilities AI discovers are the ones attackers want, and that changes the risk calculus for every organization managing an exposed surface.

Sources

Information verified against cited sources and current as of publication.

Sources


Sources and references
  1. helpnetsecurity.com
  2. thehackernews.com
  3. bleepingcomputer.com
  4. calcalistech.com
  5. cert.europa.eu
  6. thehackernews.uk