AI vulnerability exploitation has not surged, VulnCheck finds
VulnCheck found only 1.3% of publicly attributed AI-assisted vulnerability discoveries have been exploited in the wild.
By Renata Fuchs · Policy Reporter
· 3 min read
AI vulnerability exploitation has not accelerated in the way many security vendors and frontier AI labs have suggested, according to new VulnCheck research shared with The Register. VulnCheck reviewed 1,061 publicly attributed AI-assisted vulnerability discoveries tied to Anthropic's Project Glasswing and the Berkeley Vulnerability Research Initiative, then checked them against its Known Exploited Vulnerability database.
The finding was narrow but material: 14 of those vulnerabilities, or 1.3%, have been confirmed as exploited in the wild. VulnCheck said that rate is nearly the same as the exploitation rate across its broader vulnerability dataset, which undercuts the claim that AI-discovered bugs are, by default, more likely to become working attacks.
The research does not say AI is irrelevant to vulnerability discovery. It says the measurable effect so far is volume, not a higher conversion rate from discovered flaw to real-world exploitation. For security teams, that distinction matters because an increase in reported issues can still create patching pressure even if attackers are not weaponizing those issues at a higher rate.
Are AI-found vulnerabilities easier to exploit?
Based on VulnCheck's analysis, there is no public evidence yet that AI-found vulnerabilities are easier to exploit than vulnerabilities discovered through conventional research. The firm found that AI-assisted discoveries reached confirmed exploitation at about the same rate as the overall vulnerability population it tracks.
VulnCheck's report is especially pointed about Anthropic's Project Glasswing, which the AI company introduced in April with warnings that AI-assisted vulnerability discovery could help attackers take over systems, disrupt operations or steal data. Anthropic said Claude Mythos identified 23,019 vulnerability candidates, but VulnCheck said the public record shows limited follow-through on those findings.
According to VulnCheck, only 126 of the Project Glasswing candidates have been published as CVEs, and only one has been confirmed as exploited in the wild. The firm also said Anthropic's public disclosure ledger has shown little activity since the project was announced. Anthropic did not disclose, in the figures cited by VulnCheck, what happened to most of the candidate findings.
Patrick Garrity, a security researcher at VulnCheck, said AI-assisted vulnerability discovery has use for both offensive and defensive work. But he wrote that the data does not support treating AI-discovered vulnerabilities as inherently more likely to be exploited than flaws found by traditional methods.
Garrity also argued that public discussion has run ahead of the evidence. He wrote that data available so far, including Anthropic's disclosure record, suggests AI-assisted vulnerability discovery and frontier model capabilities have been "overhyped relative to the evidence available today." He added that the risk is not fictional, but that the observed impact has been "real but modest."
What attackers are exploiting instead
VulnCheck said attackers continued to exploit known vulnerabilities at scale without needing an AI-specific shift. The firm identified 495 known exploited vulnerabilities in the first half of 2026. Content management systems made up about one-third of those, while network edge devices remained a preferred target.
The report also points to a second AI-related risk for operators: AI products are becoming targets themselves. Attackers are looking for weaknesses in the fast-growing AI software stack, even as the evidence for AI-generated vulnerability exploitation remains limited.
For founders and security buyers, the takeaway is operational rather than dramatic. AI may increase the number of flaws researchers can surface, which can help defenders patch earlier. VulnCheck's data does not show that those AI-assisted findings are turning into real-world attacks at an unusual rate.
This story draws on original reporting from The Register.