AI Is Cutting the Time Criminals Need to Turn a Known Bug Into a Working Attack
Exploitation of already-patched flaws is outpacing zero-days, CVE volumes are on track to hit 96,000 this year, and the window between public disclosure and first attack has shrunk to 80 days.

Key points
- Google's Threat Intelligence Group recorded 141 exploited vulnerabilities between January and August 2026, more than all 127 exploited across the whole of 2025.
- The median time from a flaw being made public to its first confirmed use in an attack fell from 120 days in 2025 to 80 days in the first half of 2026.
- CISA projects roughly 96,000 CVEs (publicly catalogued security flaws) will be published by the end of 2026, up from 67,000 through mid-September.
- On 22 September 2026, CISA published its CVE Program: Establishing a New Quality Era Framework, calling for stronger governance, better data, and faster record accuracy across the global vulnerability-tracking system.
- A single patched flaw in enterprise remote-access software was weaponised within four days of public disclosure, with six separate criminal groups exploiting it within a week.
Criminals used to prize zero-days: flaws that software makers had not yet discovered or fixed. Increasingly, they are skipping that hunt entirely. It is cheaper, faster, and apparently just as effective to wait for a company to publish a patch, then race to attack every organisation that has not yet installed it.
This category of flaw is called an "n-day" vulnerability. The "n" stands for the number of days since the maker publicly acknowledged and patched the problem. The window between that public announcement and a working criminal attack is shrinking fast.
How fast is exploitation actually growing?
Very fast. Google's Threat Intelligence Group counted 141 vulnerabilities actively exploited in the wild from January to August 2026 alone, against 127 for the entirety of 2025, figures first reported by CSO Online. The monthly exploitation rate has risen from roughly 10.5 flaws per month last year to nearly 18 in 2026.
Zero-day exploitation also grew, but modestly: from about 8 cases a month in 2025 to 11 so far this year. N-days are the bigger story.
High-risk flaws are bearing the brunt. Exploitation of serious, high-severity vulnerabilities more than doubled, rising from 28 cases in 2025 to 75 in just the first eight months of 2026.
| Metric | 2025 | Jan, Aug 2026 |
|---|---|---|
| Total exploited flaws | 127 | 141 |
| Monthly exploitation rate | 10.5 | ~18 |
| High-risk flaws exploited | 28 | 75 |
| Median days to first exploitation | 120 | 80 |
| CVEs published (projected full-year) | ~29,000 | 96,000 (est.) |
What does AI have to do with it?
AI tools are almost certainly accelerating the process. Researchers at Google's threat group describe criminals using large language models (AI systems trained on vast amounts of text and code) to automate the comparison of old and new software versions, extract clues from patch notes, and draft working attack code far faster than a human analyst could.
North Korea's state-linked hacking group APT45 sent thousands of prompts to Google's own Gemini AI in May, researchers found, asking it to analyse known vulnerabilities and test whether published proof-of-concept attack code actually worked.
A concrete example shows what this speed means in practice. An "OS command injection" flaw, meaning a bug that lets an attacker run their own instructions on a victim's machine, was found in BeyondTrust's Privileged Remote Access and Remote Support software. An AI research agent helped discover it. Within four days of public disclosure, criminals had weaponised it for targeted attacks. Within seven days, six separate criminal groups were exploiting it.
Should ordinary people and businesses be worried?
Yes, selectively. The raw numbers sound alarming, but only about 0.23 percent of all disclosed flaws, roughly one in every 431, are ever actually exploited. The problem is choosing which fraction to prioritise.
The CISA framework published on 22 September addresses exactly this gap. The agency's plan pushes CVE records, the standardised entries in the global catalogue of known flaws, toward being more complete and machine-readable, not merely present. A security team needs to know whether a flaw has a working exploit circulating, whether criminals are actively using it, and whether it touches any of their own internet-facing systems. A tidy record number is not enough.
Farzad Bakhtiar, senior director at threat intelligence firm Flashpoint, put it plainly: a well-formed record is not necessarily an actionable one.
For businesses of any size, the practical implication is this: patch the serious, internet-facing stuff first, not last. Edge devices like firewalls and VPN gateways, collaboration platforms, and remote-access tools are where attackers are concentrating. According to Google's research, perimeter appliances and exposed enterprise services account for 25 percent of exploited vulnerabilities combined. These are also the systems that many standard security monitoring tools cannot easily see inside.
If you are a customer of any cloud service, remote-access product, or network security appliance, watch for patch notices from your vendor and ask your IT contact when they were applied. Eighty days is the median. That is not much runway.



