DataCybersecurityAI SecurityVulnerability Management

AI finds security flaws, but attackers barely care

A VulnCheck analysis shows that of over 1,000 vulnerabilities discovered by AI, only 1.3 percent are actually exploited—the same rate as conventionally reported bugs. But attacks are getting faster.

Only 1.3% of AI-discovered security vulnerabilities are exploited

AI finds security flaws, but attackers barely care

The fear of AI-driven cyberattacks may be overblown. That's what a new analysis by security firm VulnCheck reveals for the first half of 2026: Of a total of 1,061 security vulnerabilities uncovered through AI-powered search, only 14 were actually targeted by attackers—a rate of 1.3 percent. This matches exactly the exploitation rate for conventionally reported flaws.

Key takeaways

  • 1,061 AI-discovered vulnerabilities in H1 2026, 14 exploited (1.3 %)
  • Anthropic's Project Glasswing: 23,000 findings led to only 1 confirmed attack
  • Attack speed is accelerating: From 120 to 80 days between disclosure and first attack
  • New targets: AI products themselves are emerging as attack surfaces

Much noise, little danger?

The sheer volume of AI findings says little about actual risk. That's the central insight from VulnCheck's analysis. While significantly more vulnerabilities are being reported than before, the actual exploitation rate remains stable. Particularly striking: Anthropic's Project Glasswing, an AI project for vulnerability hunting, generated over 23,000 findings—but led to only 126 published entries and one confirmed attack.

This doesn't mean AI-powered vulnerability search is ineffective. Rather, it means that raw numbers alone are not a measure of real threats. Many AI-discovered flaws may be difficult to exploit, already patched, or simply uninteresting to attackers.

Attackers are getting faster

Despite stable exploitation rates, another trend is intensifying: The time between disclosure and first attack is shrinking significantly. On average, it now takes 80 days instead of 120 days as in the previous year. Roughly 200 vulnerabilities were exploited within a month, and roughly 23 percent were targeted on the day of release or earlier.

Metric 2025 2026
Median days to attack 120 80
Attacked on release day roughly 23 %
Attacked within first month ~200 cases

This is the real alarm bell: not the volume of findings, but the speed of exploitation is increasing. Security teams have less time to respond.

Content management systems in the crosshairs

Most frequently affected are content management systems for websites—they account for roughly one-third of all cases. This is a classic target because such systems are often publicly accessible and provide access to valuable data.

As a new attack surface, VulnCheck analyst Patrick Garrity identifies AI products themselves: tools for model building and agent interfaces are becoming targets. That makes sense—controlling AI systems potentially means controlling their outputs.

What this means for you

For organizations, the takeaway is nuanced: the sheer number of AI-discovered vulnerabilities shouldn't trigger panic. At the same time, shrinking response times are a genuine problem. Patch management needs to accelerate—not because there are more flaws, but because attackers are moving faster. If you deploy AI systems, you should also keep their own security in focus: they've become targets themselves.

Sources

Editorially owned by Ideal Syka. Sources and method: Newsroom & method. Tips and corrections: ai@i6eal.de.

Share
← All articles

All analyses are based on i6eal's own measurements or on clearly labelled sources. Figures are snapshots and may change; corrections are disclosed transparently.