Decoding the world of cybersecurity

Google charts faster vulnerability exploitation

Google says vulnerability disclosures doubled during 2026 while observed exploitation increased sharply, although attackers still use only a small fraction of disclosed flaws.

Google charts faster vulnerability exploitation
Summary
  • Monthly disclosures rose from 5,045 in January to 10,740 in August.
  • Average observed exploitation rose from 10.5 vulnerabilities a month in 2025 to 18 during January–August 2026.
  • Only 0.23% of disclosed vulnerabilities were observed in active exploitation.

Vulnerability disclosure and exploitation are both accelerating, but attackers remain highly selective about which flaws they use, according to new analysis from Google Threat Intelligence Group.

Google Threat Intelligence Group said monthly vulnerability disclosures more than doubled during 2026, rising from 5,045 in January to 10,740 in August. The number of vulnerabilities observed in active exploitation also increased, from a monthly average of 10.5 during 2025 to 18 between January and August 2026.

The growth does not mean attackers are exploiting anything close to the full stream of disclosed CVEs. Google calculated that only 0.23% of vulnerabilities disclosed in 2026 — roughly one in 431 — were observed in active exploitation.

That gap is central to the research. Vulnerability volume is increasing faster than most organisations could realistically process as an undifferentiated queue, while hostile activity remains concentrated on a comparatively small number of useful flaws.

Google also found that zero-day exploitation rose more modestly, from an average of eight vulnerabilities a month in 2025 to 11 during January through August 2026. Zero-days nevertheless represented 62% of vulnerabilities observed exploited during that period.

The stronger growth came from rapid weaponisation of known flaws. Exploitation of vulnerabilities carrying Google’s High-Risk classification increased from 28 during all of 2025 to 75 in the first eight months of 2026.

Edge and security appliances remained prominent attack surfaces, accounting for 14% of exploited vulnerabilities in Google’s dataset. Enterprise directory and collaboration systems accounted for another 11%, while more than 65% of exploited edge flaws carried High or Critical threat-risk ratings.

The findings align with current attacker interest in gateways, VPN products, application-delivery infrastructure, and other externally accessible systems. Such products can sit outside endpoint-monitoring coverage while providing a direct route into administrative or trusted network positions.

AI is also changing the vulnerability cycle. Google found AI-assisted discovery was producing proportionally fewer low-risk findings, more medium-risk findings, and more vulnerabilities capable of remote code execution.

Its researchers consider it possible that attackers are using large language models and automation to analyse version differences, patches, public disclosures, and proof-of-concept code more rapidly when weaponising known vulnerabilities. The report does not establish AI as the cause of the overall growth in exploitation.

Google also cautions that automated CVE assignment can inflate raw disclosure counts. Vulnerabilities containing “Linux Kernel” in their descriptions alone generated around 5,000 CVEs in the first eight months of 2026, with no observed in-the-wild zero-day exploitation among them.

That methodological point is significant for vulnerability management. Raw CVE counts can create an impression of uncontrolled risk growth while providing little information about exposure, exploitability, attacker interest, or the importance of the affected asset.

The research instead supports triage based on threat intelligence, reachability, asset role, and observed exploitation. An organisation facing more than 10,000 new disclosures in a month cannot treat every entry as equally urgent, but it can identify the much smaller set that combines realistic attack paths with evidence of hostile activity.

Google’s analysis covers disclosures from January 2025 through August 2026 and uses the company’s own vulnerability-risk ratings rather than CVSS. It is therefore a view derived from GTIG’s dataset, not a complete census of every vulnerability or exploitation event globally.

Within those limits, the direction is consistent: disclosures are growing rapidly, exploitation is increasing, and attackers continue to concentrate their effort on flaws that provide useful access to exposed enterprise infrastructure.

×