Google: Vulnerability disclosures double to 10,000 per month as AI fuels exploitation

Google's Threat Intelligence Group reports that vulnerability disclosures have doubled to over 10,000 per month in 2026. Researchers attribute this surge to the use of AI tools by hackers to scan for and weaponize existing vulnerabilities.
Why it matters
The integration of AI into cyberattacks is accelerating the lifecycle of vulnerability exploitation, posing a significant challenge to global cybersecurity infrastructure.
Vulnerability disclosures doubled between January and August, reaching a new peak of 10,740 last month, Google’s Threat Intelligence Group (GTIG) said Wednesday.
Total vulnerability disclosures began the year at 5,045 in January and had jumped to more than 10,000 for July and August.
“We found that AI is measurably changing not just the pace of vulnerability discovery and exploitation, but also the types and typical risk profiles of vulnerabilities that are being discovered,” the researchers said.
They noted that beyond the overall number of bugs being found, the number of distinct vulnerabilities disclosed and exploited during the eight month period surpassed the totals for all of 2025. There have already been 141 exploited vulnerabilities this year after 127 last year.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in