AI finds plenty of security flaws, but almost none of them get exploited

Disclosure: Some links in this article are affiliate links. AI Maestro may earn a commission if you make a purchase, at no…

By Vane August 2, 2026 1 min read
AI finds plenty of security flaws, but almost none of them get exploited

Patrick Garrity recorded 1,061 security flaws identified by artificial intelligence during the first half of 2026, yet only fourteen showed confirmed exploitation. This 1.3% rate mirrors the overall vulnerability exploitation rate, while Anthropic‘s Project Glasswing generated 23,000 findings but resulted in just one successful attack. Despite this low conversion rate, the speed of exploitation is increasing. Half of all flaws now face their first confirmed attack within 80 days of disclosure, a drop from 120 days the previous year. Approximately 200 vulnerabilities were targeted within a month as the total number of reported issues continues to climb.

Website content management systems account for a third of all cases, and AI products themselves are becoming a growing attack surface for model-building tools and agent interfaces. The sheer volume of findings tells defenders very little about actual risk because most issues remain unexploited. Security teams must distinguish between discovered flaws and those that pose a genuine threat to their infrastructure.

  • Website content management systems face the highest volume of attacks.
  • AI products are emerging as a significant new attack vector.
  • Exploitation speed has decreased from 120 to 80 days since disclosure.
Scroll to Top