Brief IA

VulnCheck: Only 1.3% of AI Vulnerabilities Exploited in 2026

⚖️ Regulation & Ethics·Tom Levy·

VulnCheck: Only 1.3% of AI Vulnerabilities Exploited in 2026

VulnCheck: Only 1.3% of AI Vulnerabilities Exploited in 2026
Key Takeaways
1VulnCheck identified 1,061 vulnerabilities discovered by AI in the first half of 2026.
2Among these vulnerabilities, only 14 were exploited, resulting in a rate of 1.3%.
3The median time to exploit these flaws decreased from 120 to 80 days.
💡Why it mattersThis highlights that, despite increased detection by AI, the risk of exploitation remains low but is becoming faster.
Le brief IA que lisent les pros

Le brief IA que les pros lisent chaque soir

Les 7 actus IA du jour, décryptées en 5 min. Gratuit.

Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.

Choisis ton rythme

Gratuit · Pas de spam · Désabonnement en 1 clic

📄
Full Analysis

VulnCheck: Only 1.3% of AI Vulnerabilities Exploited in 2026

VulnCheck has tracked the frequency with which security vulnerabilities detected by AI are actually used in attacks. For the first half of 2026, Patrick Garrity recorded 1,061 vulnerabilities attributed to AI-assisted discoveries. Fourteen of these showed confirmed exploitation. This represents 1.3%, a rate roughly identical to that of vulnerabilities in general. Anthropic's Glasswing project produced over 23,000 results, leading to 126 published entries and a single confirmed attack.

However, attacks are occurring more quickly. Half of the vulnerabilities now see their first confirmed exploitation within 80 days of disclosure, down from 120 days the previous year. Approximately 200 vulnerabilities were attacked in the month following their disclosure, even though the total number of reported vulnerabilities continues to rise.

The time elapsed between the disclosure of a vulnerability and its first confirmed exploitation during the first half of 2026 shows that 23% were exploited on the same day as their disclosure or earlier, and the median has decreased from 120 to 80 days.

Content management systems for websites are the most attacked, accounting for one-third of all cases. Garrity emphasizes that AI products themselves represent an increasing attack surface, including model-building tools and agent interfaces. In other words, the sheer volume of discoveries provides very little information to defenders about the actual risk.

Brief IA — L'actualité IA en français

L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.