GTIG Data: AI Shifts Vulnerability Profile to 50% RCE Rate, High-Risk Finds Up 167%
GTIG report documents AI measurably altering both discovery volume and vulnerability characteristics, with RCE-heavy AI finds and accelerated n-day exploitation. Raw disclosure spikes partly reflect automated CVE processes, but the 167% high-risk growth and confirmed early exploitation of AI-generated flaws are substantive. Pattern indicates threat actors now prioritize LLM-assisted patch analysis over traditional zero-day research.
GTIG's January-August 2026 dataset shows 141 exploited vulnerabilities, averaging 18 per month against 10.5 in 2025, driven mainly by n-day weaponization rather than zero-days. Automated CVE assignment in Linux kernel alone produced roughly 5,000 entries with zero observed in-the-wild exploitation, confirming volume inflation. High-risk disclosures grew 167% to 350 in August while only 0.23% of total disclosures saw exploitation. AI agents were tasked with auditing privilege boundaries, producing 58% medium-risk findings compared to 28% for conventional methods. This pattern indicates systematic deployment of LLMs to diff patches and PoCs, accelerating n-day conversion over zero-day hunting. The 2,076 AI-system CVEs tracked, half in orchestration frameworks, remain largely unexploited but establish a new attack surface. GTIG notes early confirmation of AI-discovered flaws reaching threat clusters, signaling the transition from research tool to operational vector. Official volume claims must be discounted against automated assignment artifacts, yet the risk-profile shift and n-day doubling hold independent of raw counts. Defense teams face compressed patch windows as AI lowers the barrier for rapid weaponization of disclosed flaws.
GTIG: AI-linked exploited vulnerabilities will exceed 15% of monthly total by March 2027
Sources (2)
- [1]Google Threat Intelligence Group via SecurityWeek(https://www.securityweek.com/google-ai-is-changing-the-pace-and-profile-of-vulnerability-discovery/)
- [2]CVE Program Statistics(https://cve.mitre.org/cve/)