AI-discovered vulnerabilities are arriving at roughly twice last year's rate. Almost none of them are being exploited.
The US National Vulnerabilities Database recorded 45,207 software flaws between January and 27 July, already approaching the whole of 2025, which was itself a record. On that trajectory the year ends at roughly double the 2025 total, Bloomberg reported.
The individual tallies are extraordinary. Oracle patched 1,449 vulnerabilities in its July update against 309 in the same month last year. Microsoft's July update fixed a record 622 flaws, and credited AI discovery for the surge.
This is the moment the warnings pointed at. Attackers with frontier models, a flood of fresh holes, defenders unable to patch fast enough.
It has not happened.
Exploitation never followed discovery
Vulnerability intelligence firm VulnCheck examined every known exploited vulnerability it logged in the first half of 2026. It found 495, and the conclusion is blunt.
AI-assisted discovery has been “overhyped relative to the evidence available today”, wrote Patrick Garrity, the security researcher who authored the report.
Across two datasets, VulnCheck identified 1,061 vulnerabilities attributed to AI-assisted discovery. Fourteen of them, or 1.3%, have been confirmed as exploited.
That is roughly the rate for all vulnerabilities in the period, and lower than the historical average. AI-discovered vulnerabilities do not appear to draw attackers any more than the rest.
The ratio makes it starker. Known exploited vulnerabilities grew 10% against the previous six months. Published CVEs grew 45%. The share of CVEs that end up exploited has fallen to 1.4%, from a peak of 2.7% in late 2023.
Early exploitation has not scaled at all in absolute terms. Roughly 200 CVEs reached exploited status within 31 days of publication, against 196 in 2024 and 194 in 2025.
The ledger that stopped growing
The sharpest evidence concerns Anthropic, whose Project Glasswing did more than any other launch to raise the alarm.
Anthropic opened a public disclosure ledger in May, saying Claude had identified 23,019 findings. We covered the scale at the time, when Mythos found 10,000 flaws in a month and patching could not keep up.
VulnCheck went back to check what happened next.
The ledger has never grown beyond the 1,611 entries it launched with. Of those, 126 became published CVEs. One has been confirmed as exploited in the wild.
More than 150 findings have passed the disclosure deadline set out in Anthropic's own Coordinated Disclosure Policy, Garrity writes, and the company has published no updates or new disclosures.
Garrity has tracked those disclosures in a public repository since April, so the claim is checkable rather than rhetorical.
Who is actually finding the bugs
Much of the record volume is vendors finding their own flaws. Most of the vulnerabilities Google fixed in a recent Chrome update were reported internally rather than by outsiders.
That distinction carries the whole argument. A flaw a vendor finds and patches is a flaw an attacker never reaches.
Garrity reads it the same way. Giving defenders frontier models is more likely to help them harden software than to help attackers get there first.
What did change
Two things moved, and neither is comforting.
Vulnerabilities now reach exploited status faster. The median time from CVE publication fell from 120 days in 2025 to 80 days in the first half of this year.
CISA has responded with new guidance, recommending patching within three days where there is evidence of exploitation alongside high impact or public exposure.
AI tools have also become targets. VulnCheck identified 28 known exploited vulnerabilities in AI systems and observed activity against 10 of them.
In the workflow tool LangFlow, attackers chained two flaws to gain access, harvested credentials likely intended for services such as OpenAI and Claude, deployed cryptominers and attempted to move laterally. Neither vulnerability has reached the federal catalogue.
The models themselves are part of that surface. OpenAI has confirmed its own agents broke out of a sandbox and breached Hugging Face.
The tools keep shipping regardless
None of this has slowed the market. Microsoft launched Project Perception on Monday, an agentic security system entering public preview on 3 August. Cisco has been pointing small open-weight models at bug hunting.
Garrity's caveat is worth keeping. Exploitation evidence often surfaces long after disclosure, and the major bug-hunting models were not running for the full period. Glasswing arrived in April, Microsoft's MDASH and OpenAI's Daybreak in May.
The risk is not imaginary. On the evidence so far it is real but modest, and the loudest claim about it has a ledger that stopped updating.