AI Isn't Making Vulnerabilities More Dangerous. It's Making More of Them. | Vulnerabilities.ai™ Research
← Research
July 28, 2026 · AI-Discovered Vulnerabilities
AI-Discovered Vulnerability Response

AI Isn't Making Vulnerabilities More Dangerous. It's Making More of Them.

VulnCheck published its State of Exploitation 1H-2026 report on July 28, 2026 — the most complete evidence yet on whether AI-assisted vulnerability discovery is making the threat landscape more dangerous, or just louder. The data says louder, mostly.

The Volume Is Real. The Danger Isn't Scaling With It.

VulnCheck tracked 495 Known Exploited Vulnerabilities added to its KEV catalog in the first half of 2026. CVE disclosure volume grew 45% over the same period compared to the prior six months; KEV additions grew only 10%. The resulting KEV-to-CVE ratio — 1.4% — is the lowest in years, down from a peak of 2.7% in late 2023. More vulnerabilities are being published; a shrinking share of them are actually exploited.

What AI-Assisted Discovery Actually Produced

Combining Anthropic's disclosures with the Berkeley Vulnerability Research Initiative's tracking, VulnCheck identified 1,061 vulnerabilities attributed to AI-assisted discovery in the period. Of those, 14 — 1.3% — have been confirmed exploited in the wild, roughly in line with the overall exploitation rate for all vulnerabilities disclosed in the same window, and lower than what VulnCheck has observed historically. AI increases the volume of findings without proportionally increasing how many turn into real attacks — which hands defenders more opportunity to fix things before they're exploited, not less.

Project Glasswing's Numbers Don't Match Its Ledger

The report includes a pointed look at Anthropic's Project Glasswing disclosure ledger, launched in May 2026 with a claimed 23,019 findings. Since launch, the ledger has not grown past its original 1,611 committed entries, and more than 150 findings have now passed their own 90-day disclosure deadline without being published. Of the 1,611 entries, 126 have resulted in published CVEs. One — CVE-2026-26980 — has been confirmed exploited in the wild, observed directly on VulnCheck's own canary network.

VulnCheck's own framing: the evidence so far suggests AI-assisted vulnerability discovery has been overhyped relative to what's actually been delivered. The risk isn't imaginary. The impact has been real, but modest.

AI Products Are the New Targets, Not Just the New Tools

Separately from discovery, the report identifies AI infrastructure itself as an emerging target category: 28 KEVs now affect AI products, spanning model-building tools, workload-scaling platforms, AI gateways, agents, and workflow automation. Exploitation activity has been observed on 10 of them. LangFlow is the clearest example — two CVEs (CVE-2026-0769 and CVE-2026-5027) have been used together to gain initial access, harvest credentials likely tied to services like OpenAI and Claude, deploy cryptominers, and move laterally. Neither CVE has been added to CISA's official KEV catalog; both are visible only through independent tracking.

Why This Matters Beyond the Numbers

The gap between what's actually being exploited and what's on CISA's official radar is exactly the gap an independent tracker exists to close — LangFlow's exploitation chain being invisible in CISA KEV isn't a one-off, it's the pattern. And the honest read on AI-assisted discovery a year in is neither panic nor dismissal: the volume is real, the danger is proportional rather than amplified, and the organizations running the programs — Anthropic included — aren't yet matching their own stated pace.

This site's Ledger has been updated with the corrected Glasswing figures.

See how Glasswing, QuiltWorks, Daybreak, and Gold Eagle compare — and where each AI-discovered flaw lands in your remediation timeline.
Explore Ledger →
Sources
Verified VulnCheck, "State of Exploitation 1H-2026," 28 July 2026.
Verified Berkeley Vulnerability Research Initiative disclosure data as cited in VulnCheck's report.
This brief synthesizes and cross-verifies publicly available primary sources, listed above. It is independent analysis, not first-party research.