CourionAI
EN
Newsletter
← All news
security 3 min read

AI is finding a flood of security flaws. Almost none of them get attacked

VulnCheck counted 1,061 vulnerabilities found with AI help in the first half of 2026. Fourteen were confirmed exploited, a rate of 1.3 percent, which is roughly the same as vulnerabilities found any other way.

A wall of hundreds of small keyholes receding into the distance, with only two or three holding an actual turned key

The number of software vulnerabilities found with AI assistance has exploded over the past year. The number that attackers actually use has not. Security firm VulnCheck put figures on the gap in its half-year report, and they are a useful antidote to a year of breathless coverage in both directions.

Researcher Patrick Garrity counted 1,061 vulnerabilities in the first half of 2026 that could be traced to AI-assisted discovery. Fourteen of those showed confirmed exploitation in the wild. That is 1.3 percent, which lines up almost exactly with the exploitation rate for vulnerabilities overall. Anthropic’s Project Glasswing is the starkest example of the funnel: more than 23,000 findings produced 126 published entries in the public vulnerability database, and exactly one confirmed attack.

The report is not uniformly reassuring. Attacks are landing faster than they used to. The median time from a vulnerability being disclosed to its first confirmed exploitation fell from 120 days in 2025 to 80 days in the first half of 2026, and roughly 200 flaws were attacked within a month of disclosure. About 23 percent were exploited on or before the day they were published, meaning attackers knew first. Website content management systems took the most hits, accounting for a third of all cases.

What is behind this. Two things are being confused in most coverage, and the report separates them cleanly. Finding a vulnerability is a search problem, and search is exactly what models are good at, which is why the raw count went up so sharply. Turning a vulnerability into a working attack against a specific target is a different job involving reliability, delivery and a reason to bother. That second step still filters out almost everything. So the volume of AI-assisted findings tells defenders very little about how much danger they are actually in, which is Garrity’s central point. The genuinely worrying trend in the data is not the AI column at all, it is the shrinking window between disclosure and attack, and that trend predates the current wave of tooling. Garrity does flag one thing to watch: AI products themselves, including model-building tools and agent interfaces, are becoming a target category of their own.

What this means for you: if you have been reading that AI is about to hand attackers a limitless supply of weapons, the numbers do not support that yet. If you have been reading that AI security tooling has made everyone safer, the numbers do not support that either. The practical takeaway is the boring one: patch faster. Half of all exploited flaws now get attacked within 80 days of becoming public, and if you run a website on WordPress, Drupal or a similar system, you are in the single most targeted category there is. Turning on automatic updates for your CMS and its plugins does more for you this month than any opinion about AI and security.

Sources

Source: https://www.vulncheck.com/blog/state-of-exploitation-1h-2026

Next story

AMD trained a fully open model on its own chips and published everything except a commercial licence

Instella-MoE-16B-A3B has 16 billion parameters but uses only 2.8 billion per token. AMD released the weights from every training stage, the data mixtures and the code, and licensed the weights for research only.

A wooden cabinet of sixteen small drawers with only three pulled open and lit, cooling fins and cabling along the back, an open blueprint beside it