Summary
- VulnCheck found that 14 of 1,061 AI-assisted vulnerability discoveries, or 1.3%, were confirmed as exploited in the wild.
- The exploitation rate roughly matched the overall rate across vulnerabilities in the first half of 2026.
- The finding challenges AI vulnerability hype while reinforcing the need for context-driven triage and exploitability-based remediation.
VulnCheck says vulnerabilities discovered with AI assistance are not currently being exploited in the wild at a higher rate than vulnerabilities discovered through other routes, although AI appears to be increasing disclosure volume and triage pressure.
In its State of Exploitation 1H-2026 report, VulnCheck examined 1,061 vulnerabilities attributed to AI-assisted discovery and found that 14, or 1.3%, had been confirmed as exploited in the wild. The company said the figure roughly matched the exploitation rate observed across all vulnerabilities during the first six months of 2026.
The report identified 495 known exploited vulnerabilities during the first half of the year. VulnCheck said 23.43% showed evidence of exploitation on or before the day the CVE was published, while the median time from CVE publication to known-exploited status fell from 120 days in 2025 to 80 days in the first half of 2026.
The findings create a more grounded view of AI-assisted vulnerability discovery. AI is increasing the number of potential findings and helping researchers uncover weaknesses faster, but the available data does not show that AI-discovered vulnerabilities are inherently more likely to be exploited. The operational strain comes from the volume of discoveries and the limited capacity organisations have to assess, prioritise, and remediate them.
Exploitation remains concentrated in familiar areas. Content management systems accounted for one-third of known exploited vulnerabilities in the first half of 2026, while network edge devices remained heavily targeted. Security tools, developer tools, device management platforms, desktop applications, AI systems, identity systems, virtualisation technologies, cloud services, and OT environments also appeared across the exploited-technology landscape.
AI products are becoming part of the attack surface in their own right. VulnCheck reported exploitation affecting model-building tools, workload-scaling platforms, AI gateways, agents, and workflow automation. Once these systems touch corporate information, privileged workflows, or cloud credentials, they need to be treated as production infrastructure rather than experimental tooling.
The supplied Black Duck commentary usefully separates discovery value from remediation burden. AI-generated findings should not be dismissed, especially where they identify business logic flaws, unusual data flows, or attack paths that rule-based tools miss. At the same time, AI can generate theoretical or context-poor findings that consume triage time unless enriched with data flow analysis, exploitability context, and business impact.
Vulnerability management in UK and European organisations cannot be driven by disclosure volume alone. Security teams need to distinguish internet-exposed, exploitable, business-critical, and actively exploited weaknesses from issues that are plausible but lower priority. Regulators, customers, and insurers increasingly expect evidence that risk has been assessed and acted on, not merely counted.




