
Artificial intelligence was supposed to unleash a wave of newly weaponizable software bugs on the internet. The numbers, at least so far, tell a quieter story. Despite the alarm surrounding AI vulnerability exploitation, a new analysis by VulnCheck finds that AI-discovered security flaws are being exploited at roughly the same modest rate as flaws found through traditional methods — challenging some of the more dramatic predictions that have circulated since large language models entered the security research field.
Key takeaways
- Anthropic’s Claude Mythos identified 23,019 potential vulnerability candidates, but only 126 have been published as CVEs and just one has been confirmed exploited in the wild.
- VulnCheck analyzed 1,061 AI-assisted vulnerabilities from Project Glasswing and the Berkeley Vulnerability Research Initiative and found only 14 (1.3%) confirmed exploited — matching the general exploitation rate.
- AI-assisted discovery increases the volume of found vulnerabilities but has not raised the proportion that attackers actually exploit.
- VulnCheck recorded 495 known exploited vulnerabilities in the first half of 2026, with CMS platforms and network edge devices as the main targets.
- AI products themselves are emerging as an attack surface, as adversaries hunt for weaknesses in the growing AI software stack.
Anthropic’s Project Glasswing: Big Numbers, Thin Exploitation Record
When Anthropic unveiled Project Glasswing in April, the announcement carried a serious warning: AI-assisted vulnerability discovery could let attackers hijack systems, disrupt operations, and steal data at a scale previously impossible. The numbers Anthropic put forward seemed to justify the concern.
Volume of vulnerabilities identified
Claude Mythos, Anthropic’s AI-based security research tool, may have flagged as many as 23,019 vulnerability candidates. That is a striking figure by any measure — a volume of potential security flaws that no traditional research team could feasibly produce in comparable time. It set off a genuine debate about whether AI was about to tip the balance permanently toward attackers.
Public disclosure and exploitation data
But the follow-through has been far more limited. Of those 23,019 candidates, only 126 have been formally published as CVEs — the Common Vulnerabilities and Exposures identifiers that signal a flaw has been officially recognized and catalogued. More telling still: just one vulnerability from Anthropic’s Project Glasswing disclosures has been confirmed as exploited in the wild. According to VulnCheck, Anthropic’s public disclosure record has shown little movement since the project launched, leaving the fate of the vast majority of those candidates unclear.
VulnCheck’s Analysis: What the Data Actually Shows
To move beyond the headline numbers, VulnCheck conducted a systematic analysis of 1,061 AI-assisted vulnerability discoveries publicly attributed to both Anthropic’s Project Glasswing and the Berkeley Vulnerability Research Initiative. The firm then cross-referenced those findings against its Known Exploited Vulnerability (KEV) database — the most reliable real-world signal of whether a flaw is actually being weaponized.
Cross-referencing AI-identified vulnerabilities with exploitation databases
The result was surprisingly flat. Just 14 of those 1,061 vulnerabilities — 1.3 percent — had been confirmed as exploited in the wild. That figure is nearly identical to the exploitation rate VulnCheck observes across its entire vulnerability dataset, suggesting that AI-found bugs carry no special advantage for attackers over conventionally discovered ones.
Exploitation rates compared to traditional methods
This is the finding that cuts most directly against the prevailing narrative. AI-assisted vulnerability discovery is clearly expanding the raw volume of flaws that researchers can surface. What it has not done, at least based on the data available through mid-2026, is increase the proportion of those flaws that end up exploited. More bugs found does not automatically mean more bugs turned into working attacks.
That distinction matters enormously for how organizations should think about AI-driven security risk. A flood of newly discovered vulnerabilities that largely get patched before anyone exploits them is a very different problem than a flood of vulnerabilities that attackers immediately weaponize. The data so far points toward the former.
Expert Perspective: AI as a Defender’s Tool, Not Just an Attacker’s
AI’s value for attackers and defenders
Patrick Garrity, a security researcher at VulnCheck, drew a careful line between what the data shows and what it does not. “AI-assisted vulnerability discovery clearly has value for both attackers and defenders,” he wrote. Crucially, his analysis found no evidence that AI-discovered vulnerabilities are inherently more likely to be exploited than those found through traditional research. Instead, the more defensible interpretation is that AI is helping researchers find more flaws — and giving defenders a window to patch them before criminals can exploit them.
A cautious assessment of the hype
Garrity was direct about the gap between rhetoric and evidence. “The data so far, including Anthropic’s own stalled disclosure ledger, suggests that AI-assisted vulnerability discovery and frontier capabilities have been overhyped relative to the evidence available today,” he wrote. “That doesn’t mean the risk is imaginary. It means the impact has been real but modest.”
That framing — real but modest — is analytically important. It neither dismisses the genuine shift AI represents in security research, nor accepts the more alarming claim that it is fundamentally reshaping the threat landscape in attackers’ favor. The key variable, Garrity’s analysis implies, is who is moving faster: researchers patching flaws, or adversaries weaponizing them. So far, the patching side appears to be holding its own.
Current Threat Landscape and Emerging Trends
Recent known exploited vulnerabilities
The broader exploitation picture in 2026 is still active, even if AI-discovered bugs are not driving it. VulnCheck identified 495 known exploited vulnerabilities during the first half of 2026. Content management systems accounted for roughly one-third of those, with network edge devices remaining a consistent target for attackers. These exploitation campaigns reflect adversaries continuing to work through familiar, proven attack surfaces — not a sudden AI-powered escalation.
Attackers targeting AI products themselves
One genuinely new development is worth watching. AI products themselves are becoming an increasingly attractive target for attackers. As the AI software stack expands rapidly across enterprises and infrastructure, adversaries are starting to hunt for weaknesses within those systems rather than simply using AI as a tool. That inversion — AI as both the research instrument and the attack surface — is an emerging dynamic that the current data does not yet fully capture.
The implication is that even if AI vulnerability exploitation has not yet triggered the surge some predicted, the attack surface is actively shifting. How defenders and researchers respond to vulnerabilities in AI systems themselves, where disclosure norms and patch cycles are still maturing, may determine whether the current equilibrium holds.
FAQ
How many vulnerabilities has Anthropic’s Project Glasswing identified?
Anthropic’s Project Glasswing, through Claude Mythos, identified 23,019 potential vulnerability candidates. Of those, only 126 have been formally published as CVEs.
Are AI-identified vulnerabilities exploited more often than traditional vulnerabilities?
No. According to VulnCheck’s analysis, only 1.3 percent of AI-identified vulnerabilities were confirmed as exploited in the wild — a rate that matches the general exploitation rate across all vulnerabilities in VulnCheck’s dataset.
What is the significance of AI in vulnerability discovery according to experts?
Experts say AI enables researchers to find a far greater volume of vulnerabilities, which in turn gives defenders more opportunities to patch flaws before attackers can exploit them. The net effect, based on current data, appears to benefit defenders as much as attackers.
Are AI products themselves targeted by attackers?
Yes. Attackers are increasingly targeting AI software products directly, looking for weaknesses in the expanding AI software stack — a trend that represents a new and evolving attack surface beyond the use of AI as a research tool.
Article produced with the assistance of artificial intelligence and reviewed by the editorial team.

3 hours ago
19









English (US) ·