Synthetic intelligence was alleged to unleash a wave of newly weaponizable software program bugs on the web. The numbers, no less than thus far, inform a quieter story. Regardless of the alarm surrounding AI vulnerability exploitation, a brand new evaluation by VulnCheck finds that AI-discovered safety flaws are being exploited at roughly the identical modest charge as flaws discovered by way of conventional strategies — difficult a number of the extra dramatic predictions which have circulated since massive language fashions entered the safety analysis subject.
Key takeaways
- Anthropic’s Claude Mythos recognized 23,019 potential vulnerability candidates, however solely 126 have been printed as CVEs and only one has been confirmed exploited within the wild.
- VulnCheck analyzed 1,061 AI-assisted vulnerabilities from Undertaking Glasswing and the Berkeley Vulnerability Analysis Initiative and located solely 14 (1.3%) confirmed exploited — matching the overall exploitation charge.
- AI-assisted discovery will increase the quantity of discovered vulnerabilities however has not raised the proportion that attackers really exploit.
- VulnCheck recorded 495 recognized exploited vulnerabilities within the first half of 2026, with CMS platforms and community edge gadgets as the principle targets.
- AI merchandise themselves are rising as an assault floor, as adversaries hunt for weaknesses within the rising AI software program stack.
Anthropic’s Undertaking Glasswing: Massive Numbers, Skinny Exploitation File
When Anthropic unveiled Undertaking Glasswing in April, the announcement carried a severe warning: AI-assisted vulnerability discovery might let attackers hijack programs, disrupt operations, and steal information at a scale beforehand unimaginable. The numbers Anthropic put ahead appeared to justify the priority.
Quantity of vulnerabilities recognized
Claude Mythos, Anthropic’s AI-based safety analysis software, might have flagged as many as 23,019 vulnerability candidates. That could be a hanging determine by any measure — a quantity of potential safety flaws that no conventional analysis crew might feasibly produce in comparable time. It set off a real debate about whether or not AI was about to tip the steadiness completely towards attackers.
Public disclosure and exploitation information
However the follow-through has been way more restricted. Of these 23,019 candidates, solely 126 have been formally printed as CVEs — the Widespread Vulnerabilities and Exposures identifiers that sign a flaw has been formally acknowledged and catalogued. Extra telling nonetheless: simply one vulnerability from Anthropic’s Undertaking Glasswing disclosures has been confirmed as exploited within the wild. In response to VulnCheck, Anthropic’s public disclosure report has proven little motion for the reason that venture launched, leaving the destiny of the overwhelming majority of these candidates unclear.
VulnCheck’s Evaluation: What the Information Truly Reveals
To maneuver past the headline numbers, VulnCheck carried out a scientific evaluation of 1,061 AI-assisted vulnerability discoveries publicly attributed to each Anthropic’s Undertaking Glasswing and the Berkeley Vulnerability Analysis Initiative. The agency then cross-referenced these findings towards its Recognized Exploited Vulnerability (KEV) database — essentially the most dependable real-world sign of whether or not a flaw is definitely being weaponized.
Cross-referencing AI-identified vulnerabilities with exploitation databases
The consequence was surprisingly flat. Simply 14 of these 1,061 vulnerabilities — 1.3 % — had been confirmed as exploited within the wild. That determine is almost an identical to the exploitation charge VulnCheck observes throughout its total vulnerability dataset, suggesting that AI-found bugs carry no particular benefit for attackers over conventionally found ones.
Exploitation charges in comparison with conventional strategies
That is the discovering that cuts most instantly towards the prevailing narrative. AI-assisted vulnerability discovery is clearly increasing the uncooked quantity of flaws that researchers can floor. What it has not accomplished, no less than based mostly on the info accessible by way of mid-2026, is enhance the proportion of these flaws that find yourself exploited. Extra bugs discovered doesn’t robotically imply extra bugs was working assaults.
That distinction issues enormously for a way organizations ought to take into consideration AI-driven safety danger. A flood of newly found vulnerabilities that largely get patched earlier than anybody exploits them is a really totally different drawback than a flood of vulnerabilities that attackers instantly weaponize. The info thus far factors towards the previous.
Professional Perspective: AI as a Defender’s Software, Not Simply an Attacker’s
AI’s worth for attackers and defenders
Patrick Garrity, a safety researcher at VulnCheck, drew a cautious line between what the info reveals and what it doesn’t. “AI-assisted vulnerability discovery clearly has worth for each attackers and defenders,” he wrote. Crucially, his evaluation discovered no proof that AI-discovered vulnerabilities are inherently extra more likely to be exploited than these discovered by way of conventional analysis. As a substitute, the extra defensible interpretation is that AI helps researchers discover extra flaws — and giving defenders a window to patch them earlier than criminals can exploit them.
A cautious evaluation of the hype
Garrity was direct in regards to the hole between rhetoric and proof. “The info thus far, together with Anthropic’s personal stalled disclosure ledger, means that AI-assisted vulnerability discovery and frontier capabilities have been overhyped relative to the proof accessible in the present day,” he wrote. “That doesn’t imply the chance is imaginary. It means the impression has been actual however modest.”
That framing — actual however modest — is analytically necessary. It neither dismisses the real shift AI represents in safety analysis, nor accepts the extra alarming declare that it’s essentially reshaping the risk panorama in attackers’ favor. The important thing variable, Garrity’s evaluation implies, is who’s transferring sooner: researchers patching flaws, or adversaries weaponizing them. To this point, the patching facet seems to be holding its personal.
Present Menace Panorama and Rising Tendencies
Latest recognized exploited vulnerabilities
The broader exploitation image in 2026 remains to be energetic, even when AI-discovered bugs will not be driving it. VulnCheck recognized 495 recognized exploited vulnerabilities through the first half of 2026. Content material administration programs accounted for roughly one-third of these, with community edge gadgets remaining a constant goal for attackers. These exploitation campaigns mirror adversaries persevering with to work by way of acquainted, confirmed assault surfaces — not a sudden AI-powered escalation.
Attackers concentrating on AI merchandise themselves
One genuinely new improvement is value watching. AI merchandise themselves have gotten an more and more engaging goal for attackers. Because the AI software program stack expands quickly throughout enterprises and infrastructure, adversaries are beginning to hunt for weaknesses inside these programs quite than merely utilizing AI as a software. That inversion — AI as each the analysis instrument and the assault floor — is an rising dynamic that the present information doesn’t but totally seize.
The implication is that even when AI vulnerability exploitation has not but triggered the surge some predicted, the assault floor is actively shifting. How defenders and researchers reply to vulnerabilities in AI programs themselves, the place disclosure norms and patch cycles are nonetheless maturing, might decide whether or not the present equilibrium holds.
FAQ
What number of vulnerabilities has Anthropic’s Undertaking Glasswing recognized?
Anthropic’s Undertaking Glasswing, by way of Claude Mythos, recognized 23,019 potential vulnerability candidates. Of these, solely 126 have been formally printed as CVEs.
Are AI-identified vulnerabilities exploited extra typically than conventional vulnerabilities?
No. In response to VulnCheck’s evaluation, only one.3 % of AI-identified vulnerabilities had been confirmed as exploited within the wild — a charge that matches the overall exploitation charge throughout all vulnerabilities in VulnCheck’s dataset.
What’s the significance of AI in vulnerability discovery in line with consultants?
Consultants say AI allows researchers to discover a far larger quantity of vulnerabilities, which in flip provides defenders extra alternatives to patch flaws earlier than attackers can exploit them. The web impact, based mostly on present information, seems to profit defenders as a lot as attackers.
Are AI merchandise themselves focused by attackers?
Sure. Attackers are more and more concentrating on AI software program merchandise instantly, searching for weaknesses within the increasing AI software program stack — a pattern that represents a brand new and evolving assault floor past the usage of AI as a analysis software.
Article produced with the help of synthetic intelligence and reviewed by the editorial crew.
