HomeVulnCheck data questions AI vulnerability discovery riskUncategorizedVulnCheck data questions AI vulnerability discovery risk

VulnCheck data questions AI vulnerability discovery risk

New research from VulnCheck complicates warnings that AI-assisted vulnerability discovery is making exploitation more dangerous.

The vulnerability research firm published its H1 2026 exploitation report this month, tracking every Known Exploited Vulnerability (KEV) added to its own database against CVE publication dates. The report follows months of warnings, including from Anthropic, that AI systems capable of finding flaws in code could hand attackers a faster route to weaponisation. VulnCheck’s numbers tell a mixed story instead.

Exploitation now lands faster once a CVE goes public. AI-attributed vulnerabilities, however, show no higher exploitation rate than anything else in the KEV catalogue. Security teams tuning patch queues around AI-generated alerts are working from a smaller gap than the warnings suggest.

The exploitation clock is moving faster than the disclosure clock

VulnCheck identified 495 KEVs in the first six months of 2026. According to the firm’s tally, 23.43 percent showed evidence of exploitation on or before the day the CVE was published, down from 28.93 percent across all of 2025. Fewer flaws are being caught already under attack at disclosure time.

The firm’s data puts the median gap between CVE publication and KEV status at 80 days in the first half of 2026, down from 120 days across 2025. Fewer vulnerabilities arrive pre-weaponised. The ones that don’t are catching up fast once they’re public.

CISA’s Binding Operational Directive 26-04, issued this year, tells federal agencies to patch within three days when a vulnerability shows evidence of exploitation, is automatable, carries high technical impact, or sits exposed on the public internet.

Remediation windows built around a 120-day timeline in 2025 no longer match the pace of exploitation. A gap that’s shrunk by a third in six months leaves little room for quarterly patch cycles or change-advisory-board queues that take weeks to clear.

Vulnerability disclosure has grown for years, and VulnCheck wanted to know whether confirmed exploitation was growing at the same rate (spoiler: it isn’t.)

The ratio of new KEVs to newly published CVEs peaked at 2.7 percent in the second half of 2023 and has fallen to 1.4 percent in the first half of 2026. CVE volume grew 45 percent over the prior six months. KEV volume grew only 10 percent.

Some of that gap will close over time, since attackers often weaponise flaws months or years after disclosure. VulnCheck’s cohort analysis found roughly 200 CVEs reaching KEV status within 31 days of publication in the first half of 2026, essentially flat against 196 in 2024 and 194 in 2025.

Early exploitation isn’t accelerating, it’s holding steady while the denominator – published CVEs – keeps climbing.

Primary attack surfaces: CMS, edge devices, and AI infrastructure

CMS platforms accounted for one-third of all KEVs VulnCheck added during the period, a larger share than the category has held in prior periods of VulnCheck’s data.

Unsurprisingly, WordPress plugins account for most of that volume, though Drupal, Ghost, and Kentico Xperience all show up in the figures as well. The Australian Signals Directorate issued an advisory this month on a large-scale campaign targeting website content management systems, matching what VulnCheck observed independently.

Plugin ownership on multi-site WordPress deployments often sits with marketing or product teams rather than security, which makes it one of the harder asset categories to track consistently. Patching a CMS with an active plugin ecosystem isn’t something that can wait for a quarterly maintenance window.

Edge devices remain a steady source of new KEVs. Cisco, Palo Alto, Check Point, F5, Juniper, Fortinet, SonicWall, Ubiquiti, TOTOLINK, Tenda, D-Link, Netgear, and Linksys all had new entries in the first half of 2026, according to VulnCheck.

CISA issued BOD 26-02 during the same window, directing agencies to address the risk posed by edge devices that have reached the end of support. Hardware refresh cycles for firewalls and VPN concentrators tend to run on multi-year schedules. The exploitation data suggests attackers aren’t waiting for those cycles to finish.

Separate from AI-assisted discovery, AI infrastructure itself is showing up as a target. VulnCheck says it has logged exploitation activity across 10 of the 28 AI-system KEVs identified through its Canary network, which monitors live, internet-exposed hosts rather than sandboxed test environments.

Attackers exploiting CVE-2026-0769 and CVE-2026-5027 in LangFlow gained initial access, harvested credentials for services including OpenAI and Claude, deployed cryptominers, and attempted lateral movement, according to the firm. As of publishing, neither flaw has been added to CISA’s KEV catalogue.

AI-discovered flaws see no exploitation bump

Anthropic warned in April, when it announced Project Glasswing, that AI-assisted vulnerability discovery could let attackers hijack systems, disrupt operations, or steal data faster than defenders can respond. VulnCheck set out to test that claim, tracking Anthropic’s disclosures against its own KEV database and later adding data from the Berkeley Vulnerability Research Initiative once that project launched.

Across both datasets, 1,061 vulnerabilities carry an AI-assisted discovery attribution. Fourteen of them (1.3%) have been confirmed exploited in the wild, and VulnCheck says four of those were observed hitting its own canaries. That rate tracks closely with exploitation across all vulnerabilities disclosed in the same period. It sits below the exploitation rate seen in prior periods overall.

AI tools appear to be finding more vulnerabilities. So far, that hasn’t translated into attackers exploiting them any faster than flaws found the traditional way. VulnCheck’s reading is that the volume increase cuts both ways: defenders who patch quickly get first use of the findings as often as attackers do.

Confirmed exploits from this pool span both commercial software, including Microsoft Windows and BeyondTrust, and open-source projects such as Ghost and Chef, too small a sample yet to draw conclusions about which vendors carry the most exposure.

The disclosure ledger Anthropic launched in May claimed 23,019 findings from Claude, with 1,611 entries committed at launch. VulnCheck reports that the ledger has not grown beyond that original count since, despite more than 150 findings having passed their disclosure deadline under Anthropic’s own coordinated disclosure policy.

126 of the findings that have surfaced carry published CVEs, VulnCheck’s tracking shows. Just one, CVE-2026-26980, has been confirmed exploited in the wild, and the firm reports observing exploits against it on its own canaries.

Who catches exploitation first

79 distinct sources reported first evidence of exploitation during the first half of 2026, per VulnCheck’s tally. Patchstack led with 70 KEVs, followed by CrowdSec (64), ShadowServer (57), VulnCheck itself (37), Wordfence (20), and CISA (19).

VulnCheck’s own CVE Numbering Authority issued 34 of the 495 KEVs identified during the period, part of an effort the firm describes as getting identifiers assigned and exploitation evidence published before attackers gain a lead.

CISOs deciding where to point patch management resources should watch CMS and edge device advisories from Patchstack, ShadowServer, and CISA ahead of vendor bulletins, since those sources caught exploitation first more often than the vendors themselves during the period.

The AI discovery hype hasn’t produced evidence of faster or more dangerous exploitation yet. Anthropic’s own ledger, stalled at 1,611 entries since May, is the strongest sign the volume warnings arrived ahead of the exploitation data needed to back them up.

See also: MAI-Cyber-1-Flash: Microsoft targets vulnerability scanning costs

Banner for Cyber Security Expo by TechEx events.

Want to learn more about cybersecurity from industry leaders? Check out Cyber Security & Cloud Expo taking place in Amsterdam, California, and London. The comprehensive event is part of TechEx and is co-located with other leading technology events including the AI & Big Data Expo. Click here for more information.

Developer is powered by TechForge Media. Explore other upcoming enterprise technology events and webinars here.

Home
Services
Careers
Call Us
Contact