
AI finds plenty of security flaws, but almost none of them get exploited
Quick Answer
In the first half of 2026, AI-assisted discovery identified 1,061 vulnerabilities, with only 14 (1.3%) confirmed exploited.
Quick Take
The time to first confirmed exploit decreased to 80 days, with website content management systems being the most targeted.
Key Points
- AI-assisted tools identified over 23,000 findings, leading to 126 published entries.
- Half of all flaws see exploitation within 80 days of disclosure, down from 120 days.
- Website content management systems account for one-third of all confirmed attacks.
- AI products, including model-building tools, are increasingly targeted by attackers.
- The volume of findings provides little insight into actual risk for defenders.
📖 Reader Mode
~1 min readVulnCheck counted how often the security flaws that AI turns up are ever used in an attack. For the first half of 2026, Patrick Garrity counts 1,061 vulnerabilities traced to AI-assisted discovery. Fourteen showed confirmed exploitation. That's 1.3%, roughly the same rate as vulnerabilities overall. Anthropic's Project Glasswing produced more than 23,000 findings, which led to 126 published entries and a single confirmed attack.
Attacks are landing faster, though. Half of all flaws now see their first confirmed exploitation within 80 days of disclosure, down from 120 days the year before. About 200 were attacked within a month, even as the total number of reported vulnerabilities keeps climbing.

Website content management systems take the most hits, accounting for a third of all cases. Garrity flags AI products themselves as a growing attack surface, including model-building tools and agent interfaces. The sheer volume of findings, in other words, tells defenders very little about actual risk.
— Originally published at the-decoder.com
Want this in your inbox every morning?
Daily brief at your local 8am — bilingual EN/中文, free.
More from The Decoder
See more →
An AI model programmed nonstop for 19 days on a single MirrorCode task that cost $2,600 to run
Epoch AI's MirrorCode benchmark reveals Claude Opus 4.7 as the leader with a 56% solve rate, reconstructing a 16,000-line toolkit in 14 hours. Despite this, all models tested struggle with the most complex tasks, highlighting limitations in current AI capabilities. The single task consumed $2,600 over 19 days, raising questions about cost-effectiveness in AI development.

