Security

VulnCheck: Attackers exploit only 1.3 percent of AI vulnerabilities

4 min read
A robotic arm holds a magnifying glass in front of a wall full of gray padlocks, of which only two light up red. Image generated with GPT Image 2
A robotic arm holds a magnifying glass in front of a wall full of gray padlocks, of which only two light up red.

TL;DR Too Long; Didn’t read

Only 1.3 percent of the security vulnerabilities discovered with AI tools in the first half of 2026 were attacked, according to VulnCheck – 14 out of 1061 cases. The rate is roughly equivalent to that of traditionally found vulnerabilities. In Anthropic's Project Glasswing, only one out of over 23,000 reported findings has been targeted so far. Time to first attack dropped industry-wide from 120 to 80 days.

Key takeaways

  • VulnCheck analyzed 1061 security vulnerabilities found with AI tools in the first half of 2026.
  • Only 14 of them showed verifiable signs of active exploitation during the observation period.
  • Anthropic's Project Glasswing produced over 23,000 findings, but only 126 published CVE entries.
  • The median time to a confirmed first attack shrank industry-wide from 120 to 80 days.
  • Content management systems like WordPress and Drupal accounted for about a third of all newly exploited vulnerabilities.
  • For the first time, AI-specific tools like the platform Langflow also appear as targets in the statistics.

The security company VulnCheck has systematically evaluated for the first time how often security vulnerabilities found with AI support are actually exploited for attacks. Of 1061 AI findings recorded in the first half of 2026, the company confirmed only 14 as being actively exploited. This corresponds to a rate of 1.3 percent, hardly higher than the overall vulnerability stock. The much-touted acceleration of the wave of attacks through AI has thus far not materialized.

VulnCheck examines more than a thousand AI findings

For the report State of Exploitation 1H-2026, analyst Patrick Garrity collected data on security vulnerabilities from the first half of 2026. Specifically, findings that were discovered using AI tools were evaluated. 1061 such findings met the evaluation criteria. Four of the 14 confirmed attacks were detected by VulnCheck through its own early warning systems called Canaries. The rate of 1.3 percent is close to the average value of all vulnerabilities recorded in the same period. It is even below historical comparison values from previous years. The underlying numbers come from VulnCheck’s own database and are independently unverified. Across the entire industry, the ratio of actively exploited to total reported vulnerabilities has also shrunk. It fell from 2.7 percent at the end of 2023 to now 1.4 percent. The reason for this is that the number of reported vulnerabilities is growing faster than the number of actual attacks. Initial indications of active exploitation are primarily provided by specialized services such as Patchstack, CrowdSec, ShadowServer, and Wordfence. These reports are supplemented by data from the US agency CISA. The report thus far does not confirm publicly discussed concerns about an AI-triggered “exploitation apocalypse.”

Project Glasswing delivers volume, but few hits

The discrepancy is particularly evident in Anthropic’s automated program Project Glasswing. In June 2026, it caused a sudden increase in reported CVEs at around 200 partner organizations. Of more than 23,000 original findings, only 126 have so far resulted in published CVE entries. Only one vulnerability has been attacked so far, identified as CVE-2026-26980, which further underscores the low hit rate. A separate disclosure ledger of the program is also stalled at 1611 entries. More than 150 of these are already past the agreed disclosure deadline. Security researchers had already warned during the CVE increase in early summer: it is not the finding, but the verifying and patching of vulnerabilities that is the actual bottleneck. The new VulnCheck numbers support this assessment. That AI-supported findings are not automatically more dangerous was already demonstrated by the example of GPT-5.6 Sol Ultra. The model found a critical WordPress vulnerability for around 25 dollars. According to security firm watchTowr, however, actual attacks began quickly there – evidence that individual cases vary greatly depending on the target system.

Attacks frequently target content management systems

The total number of reported vulnerabilities grew by 45 percent in the first half of 2026, according to VulnCheck. The number of actually actively exploited vulnerabilities, by contrast, only increased by 10 percent. Content management systems such as WordPress, Drupal, Ghost, and Kentico Xperience accounted for about one-third of all newly confirmed attacked vulnerabilities. Part of this ran through a large-scale campaign, which was also documented by the Australian Signals Directorate. The fastest to be attacked after disclosure were security tools themselves, such as those from Splunk and Microsoft Defender. Developer tools and device management systems were also among the preferred targets. At the same time, the average time between a CVE publication and the first confirmed attack decreased from 120 to 80 days. Around 200 vulnerabilities were already exploited within the first 31 days. AI-specific tools have also emerged as targets in the statistics for the first time. The workflow platform Langflow, for example, which had previously been targeted by a hacker attempting automated attacks with DeepSeek support, was actually compromised through two separate vulnerabilities, according to VulnCheck. Attackers used them, among other things, to deploy cryptocurrency miners.

It will be crucial whether security teams adjust their prioritization. The findings suggest that reported vulnerabilities should continue to be evaluated based on target system and attack surface. Whether a vulnerability was discovered by AI or a human apparently plays little role. At the same time, the reduced response time from 120 to 80 days increases the pressure to deploy patches faster. Whether the gap between the volume of AI findings and actual exploitation widens further in the second half of the year will also depend on how many of the more than 150 overdue Glasswing reports are disclosed by then.

Frequently asked questions

Does the low attack rate mean AI-discovered security vulnerabilities are harmless?

No. The study only shows that AI findings are not attacked more often on average than traditionally discovered vulnerabilities – individual AI findings such as a WordPress vulnerability from GPT-5.6 Sol Ultra were still exploited quickly.

Who is behind the VulnCheck report?

VulnCheck is a US security company specialized in vulnerability and exploit data. Analyst Patrick Garrity evaluated data from the first half of 2026 for the report.

What is Project Glasswing?

Project Glasswing is Anthropic's automated program for AI-assisted vulnerability discovery, which works with around 200 partner organizations such as Cloudflare and Microsoft.

Which systems are particularly at risk according to the report?

Content management systems like WordPress, Drupal, and Ghost accounted for about a third of all confirmed attacks in the first half of 2026, alongside security and developer tools.

What role does response time play for security teams?

The median time to a first attack dropped from 120 to 80 days. That leaves security teams less time to deploy patches after a vulnerability is disclosed – regardless of how it was found.

Sources

  1. VulnCheck: State of Exploitation 1H-2026
  2. The Register: AI-found bugs aren't proving any easier to exploit despite the hype

← Back to the blog