The security company VulnCheck has systematically evaluated for the first time how often security vulnerabilities found with AI support are actually exploited for attacks. Of 1061 AI findings recorded in the first half of 2026, the company confirmed only 14 as being actively exploited. This corresponds to a rate of 1.3 percent, hardly higher than the overall vulnerability stock. The much-touted acceleration of the wave of attacks through AI has thus far not materialized.
VulnCheck examines more than a thousand AI findings
For the report State of Exploitation 1H-2026, analyst Patrick Garrity collected data on security vulnerabilities from the first half of 2026. Specifically, findings that were discovered using AI tools were evaluated. 1061 such findings met the evaluation criteria. Four of the 14 confirmed attacks were detected by VulnCheck through its own early warning systems called Canaries. The rate of 1.3 percent is close to the average value of all vulnerabilities recorded in the same period. It is even below historical comparison values from previous years. The underlying numbers come from VulnCheck’s own database and are independently unverified. Across the entire industry, the ratio of actively exploited to total reported vulnerabilities has also shrunk. It fell from 2.7 percent at the end of 2023 to now 1.4 percent. The reason for this is that the number of reported vulnerabilities is growing faster than the number of actual attacks. Initial indications of active exploitation are primarily provided by specialized services such as Patchstack, CrowdSec, ShadowServer, and Wordfence. These reports are supplemented by data from the US agency CISA. The report thus far does not confirm publicly discussed concerns about an AI-triggered “exploitation apocalypse.”
Project Glasswing delivers volume, but few hits
The discrepancy is particularly evident in Anthropic’s automated program Project Glasswing. In June 2026, it caused a sudden increase in reported CVEs at around 200 partner organizations. Of more than 23,000 original findings, only 126 have so far resulted in published CVE entries. Only one vulnerability has been attacked so far, identified as CVE-2026-26980, which further underscores the low hit rate. A separate disclosure ledger of the program is also stalled at 1611 entries. More than 150 of these are already past the agreed disclosure deadline. Security researchers had already warned during the CVE increase in early summer: it is not the finding, but the verifying and patching of vulnerabilities that is the actual bottleneck. The new VulnCheck numbers support this assessment. That AI-supported findings are not automatically more dangerous was already demonstrated by the example of GPT-5.6 Sol Ultra. The model found a critical WordPress vulnerability for around 25 dollars. According to security firm watchTowr, however, actual attacks began quickly there – evidence that individual cases vary greatly depending on the target system.
Attacks frequently target content management systems
The total number of reported vulnerabilities grew by 45 percent in the first half of 2026, according to VulnCheck. The number of actually actively exploited vulnerabilities, by contrast, only increased by 10 percent. Content management systems such as WordPress, Drupal, Ghost, and Kentico Xperience accounted for about one-third of all newly confirmed attacked vulnerabilities. Part of this ran through a large-scale campaign, which was also documented by the Australian Signals Directorate. The fastest to be attacked after disclosure were security tools themselves, such as those from Splunk and Microsoft Defender. Developer tools and device management systems were also among the preferred targets. At the same time, the average time between a CVE publication and the first confirmed attack decreased from 120 to 80 days. Around 200 vulnerabilities were already exploited within the first 31 days. AI-specific tools have also emerged as targets in the statistics for the first time. The workflow platform Langflow, for example, which had previously been targeted by a hacker attempting automated attacks with DeepSeek support, was actually compromised through two separate vulnerabilities, according to VulnCheck. Attackers used them, among other things, to deploy cryptocurrency miners.
It will be crucial whether security teams adjust their prioritization. The findings suggest that reported vulnerabilities should continue to be evaluated based on target system and attack surface. Whether a vulnerability was discovered by AI or a human apparently plays little role. At the same time, the reduced response time from 120 to 80 days increases the pressure to deploy patches faster. Whether the gap between the volume of AI findings and actual exploitation widens further in the second half of the year will also depend on how many of the more than 150 overdue Glasswing reports are disclosed by then.


