Few AI-Discovered Vulnerabilities Actually Exploited, Says VulnCheck Analysis
Anthropic
VulnCheck analyzed how often AI-discovered security vulnerabilities are actually exploited. Of 1,061 such vulnerabilities in H1 2026, only 14 (1.3%) had confirmed attacks, a rate similar to all vulnerabilities. However, exploitation is faster: average time from disclosure to first attack dropped to 80 days from 120.
VulnCheck counted how often security vulnerabilities found by AI are actually attacked. Patrick Garrity reports that in the first half of 2026 there were 1,061 vulnerabilities from AI-supported search, of which 14 (1.3%) had confirmed attacks, matching the rate for all other vulnerabilities. For Anthropic's Project Glasswing, over 23,000 findings led to 126 published entries and one confirmed attack. Despite this, exploitation is faster: the average time between publication and first confirmed attack is now 80 days, down from 120 the previous year. About 200 vulnerabilities were attacked within one month, even though significantly more vulnerabilities are reported now than before. Web content management systems are the most affected, accounting for a third of cases. Garrity also names AI products themselves as a new attack surface, including tools for model building and interfaces for agents. The sheer number of findings says little about the real risk.
Source: The Decoder (DE) —
original
