AI vulnerabilities report shows only 1% have been exploited. This data challenges fears of an impending vulnpocalypse in the cybersecurity landscape.
A recently published report by VulnCheck has revealed a glaring truth: only 1.3% of vulnerabilities identified through AI-assisted discovery have been exploited in real-world scenarios. The researchers examined 1,061 vulnerabilities discovered by AI, confirming that just 14 have been exploited. These numbers serve as a frigid reminder to cybersecurity professionals caught in the hype surrounding AI's role in vulnerability discovery. While executives scramble to brace against an anticipated onslaught of AI-discovered vulnerabilities, the reality starkly diverges from their alarmist predictions.
Diving deeper into the findings, it’s clear that panic surrounding AI vulnerabilities is largely unfounded. The distressing narrative of a looming 'vulnpocalypse' promoted by industry commentators doesn’t hold up under scrutiny. For instance, Anthropic's Project Glasswing has produced an astonishing 23,000 findings, yet only 126 of these have been assigned a Common Vulnerabilities and Exposures (CVE) designation, with just one confirmed exploit. This suggests that while AI tools have significantly ramped up the number of potential vulnerabilities we can identify, the actual exploitation rates remain minimal. The churn of vulnerability discovery doesn’t equate to a comparable surge in exploitation — a crucial takeaway for organizations navigating the murky waters of AI-driven security risks.
While the results may initially appear concerning, there is another key insight to examine: the median time to exploit known exploited vulnerabilities (KEVs) is decreasing. The report notes that this timeframe has shrunk from an average of 120 days in 2025 to around 80 days in early 2026. On the surface, this trend could incite alarm, yet it highlights a different aspect of the vulnerability landscape. Attackers are honing their skills and acting more swiftly against known threats, creating an imperative for rapid response and patching protocols. However, this agility does not extend as dramatically to newly discovered vulnerabilities, as seen by the steady pace of exploitation relative to the growing number of CVEs. Without additional context, it’s easy to misinterpret these shifts as harbingers of chaos.
In light of these findings, it becomes increasingly apparent that AI tools can actually provide a defensive advantage rather than simply a pathway for attackers. As the report underscores, the low exploitation rate of AI-discovered vulnerabilities indicates that cyber defenders have time to mitigate risks. The uptick in vulnerabilities identified doesn't translate directly to an insurmountable crisis; rather, it creates an opportunity for organizations to bolster their security posture proactively. Solid vulnerability management processes alongside robust incident response plans are crucial to mitigate identified risks before they escalate into full-blown incidents.
What should organizations take away from this research? First, they need to strip away the sensationalist narratives surrounding AI vulnerabilities and focus on the tangible data. With only a fraction of vulnerabilities actively exploited, it’s clear that reported exploits are not keeping pace with discovery rates, creating a false sense of urgency. Second, the decline in time to exploit existing vulnerabilities should motivate organizations to prioritize rapid response and patch cycles for known threats. This dual approach of proactive monitoring for newly discovered vulnerabilities and rapid reaction to existing ones can create a more effective security landscape. Finally, embracing AI tools isn't merely about defending against potential future exploitations; it’s about leveraging them to create a more resilient organization that can withstand whatever threats emerge later.
The imperative is clear: ease the narrative of urgency surrounding AI vulnerabilities. Instead, focus on optimizing your vulnerability triage and remediation workflows. While 99% of vulnerabilities may lay dormant for now, don't surrender the proactive posture your organization needs to stay ahead. This isn’t about overcoming a wave of threats; it’s about smartly using the tools at hand to turn vulnerability discovery into organizational resilience.
This perspective is generated by an AI designed to provide actionable insights and does not represent any particular cybersecurity firm or individual's view.
https://www.infosecurity-magazine.com/news/one-percent-ai-vulnerabilities