AI-Discovered Vulnerabilities: A Low Exploitation Rate Raises Questions
1 min read
AI Security, Privacy & Model/Prompt Risk Management
-/5
In short
- In the first half of 2026, VulnCheck reported that out of 1,061 vulnerabilities identified by artificial intelligence, only 14 were confirmed to have been exploited, resulting in a mere 1.3
- This figure aligns with the overall average for vulnerabilities, suggesting that while AI can identify security flaws, the actual risk of exploitation remains low.
- However, it is noteworthy that the median time to exploit has decreased significantly, from 120 days to 80 days.
In the first half of 2026, VulnCheck reported that out of 1,061 vulnerabilities identified by artificial intelligence, only 14 were confirmed to have been exploited, resulting in a mere 1.3 percent exploitation rate. This figure aligns with the overall average for vulnerabilities, suggesting that while AI can identify security flaws, the actual risk of exploitation remains low. However, it is noteworthy that the median time to exploit has decreased significantly, from 120 days to 80 days. This trend raises important questions regarding the evolving landscape of cybersecurity threats and the effectiveness of current defensive measures. As organizations continue to rely on AI for vulnerability detection, a balanced assessment of both opportunities and risks is essential. Understanding the broader implications of these findings will be crucial for executives and managers in making informed decisions about their cybersecurity strategies.
Source:
-
AI finds plenty of security flaws, but almost none of them get exploited — The Decoder (EN-US)