Skip to content
TECH CEO Daily

Vulnerability disclosures doubled to 10,740 a month, Google says, as AI reshapes attacks

Google counted 141 exploited flaws in eight months, more than all of 2025, and says attackers now turn known bugs into working attacks within days.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1Google counted 10,740 vulnerability disclosures in August 2026, up from 5,045 in January.
  • 2Attackers exploited 141 distinct flaws from January to August 2026, versus 127 in all of 2025.
  • 3Google urges a shift from mass patching to triage driven by threat intelligence, with faster fixes at the network edge.

The news

Vulnerability disclosures doubled in 2026, Google Threat Intelligence Group (GTIG) said in a report published September 30, rising from 5,045 in January to 10,740 in August. Its researchers say AI is changing how fast flaws are found and how fast they are attacked.

Exploitation is rising too. GTIG counted 141 distinct vulnerabilities exploited from January through August 2026, already more than the 127 it counted for all of 2025. That is an average of 18 a month, up from 10.5 a month in 2025. Zero-days, flaws attacked before a fix exists, rose from an average of 8 a month to 11. Exploitation of flaws GTIG rates as high-risk went from 28 in 2025 to 75 in the first eight months of 2026.

The report says most of that growth comes from the rapid weaponization of n-days: flaws that are already disclosed or patched. GTIG suggested attackers may be using AI tools to compare product versions, patches, advisories and proof-of-concept code, rather than hunting for new zero-days. Its example is CVE-2026-1731, an unauthenticated command-injection flaw in BeyondTrust's Privileged Remote Access and Remote Support products. The Record reports the bug was found autonomously by a research agent called Hacktron AI. GTIG saw one threat cluster exploiting it within four days of disclosure and five more within seven days.

AI-found bugs also tend to be more serious. According to GTIG, 50% of the vulnerabilities it tagged as AI-discovered could lead to remote code execution, meaning an attacker can run their own commands on the target, compared with 26% of other disclosed flaws.

Two cases reported by SecurityWeek show the pattern. Rejetto HTTP File Server (HFS), an open-source file server, had a flaw, CVE-2026-61500 rated 9.3 out of 10, that Horizon3.ai researchers found in June using Anthropic's Mythos model. It was fixed in version 3.2.1 on July 13. On October 2, VulnCheck warned of small-scale reconnaissance targeting it from a China Telecom IP address, with attempts against systems in Japan and the US.

In the second case, Microsoft found that exploitation of a Zimbra Collaboration Suite flaw, CVE-2026-73570, started after the July 20 fix but before the August 13 public disclosure. Attackers installed web shells, gained root access, went after authentication secrets and used Zimbra's own SSH identity to reach other servers in the cluster, according to SecurityWeek's October 1 account of Microsoft's report.

The numbers

Disclosures, August 2026
10,740
Disclosures, January 2026
5,045
Flaws exploited, Jan-Aug 2026
141 (127 in all of 2025)
High-risk flaws exploited
75 in Jan-Aug 2026 vs 28 in 2025
Share of disclosed flaws seen exploited in 2026
0.23% (about 1 in 431)
Exploited flaws hitting edge and security appliances
14%

Why CEOs should care

For CISOs, the core problem is time. Many patch programs run on a monthly cycle, but GTIG watched attackers exploit the BeyondTrust flaw within four days of disclosure. Ask your team two questions: how many days does it take us to patch an internet-facing system after a vendor advisory, and do we rank fixes by evidence of real-world exploitation or only by severity score? GTIG found that just 0.23% of flaws disclosed in 2026 were seen exploited, so the job is picking the right few, not patching everything at once. The report calls for moving from unprioritized mass patching to triage driven by threat intelligence.

Give edge devices their own fast lane. GTIG says 14% of the flaws exploited from January to August hit edge and security appliances such as VPNs and firewalls. The Zimbra case shows a quiet vendor update can be the only warning before attacks begin, and the Rejetto case shows systems left on old versions stay exposed months after a fix ships. Keep an up-to-date inventory of exposed systems and their versions.

For CFOs and boards, doubling disclosure volume means more triage work for the same security staff. Ask whether vulnerability management budgets and tools were sized for last year's volume, and ask key software suppliers whether they run AI-based code review before release, which GTIG recommends to catch flaws before they ship.

The bigger picture

Other data points the same way. The Record reports CISA counted more than 67,000 new CVEs (Common Vulnerabilities and Exposures, the standard IDs for public flaws) published in 2026, with projections of 96,000 by year-end, and that annual submissions to NIST's National Vulnerability Database rose 263% between 2020 and 2025. The kind of AI-assisted analysis that helped researchers find the Rejetto bug could also help attackers studying patches, the risk GTIG describes.

GTIG frames the moment as a window of opportunity for defenders to strengthen triage and code review before attackers scale up their own use of AI.

What’s next

Watch whether monthly disclosures keep climbing past August's 10,740 in GTIG's next update, and whether more vendors adopt AI code review before release. GTIG says that if pre-release review becomes standard practice, the growth in public disclosures could eventually slow.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Companies in this story

GoogleVulnerability managementBeyondTrustZimbraMicrosoft

Earlier coverage of Google

All Google coverage →

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.