
New research from Google reveals how AI is finding software vulnerabilities and weaknesses that are more likely to give attackers deeper access to vulnerable systems.
The Google Threat Intelligence Group found that half of the vulnerabilities identified with the help of AI could lead to remote code execution, compared with 26% of vulnerabilities discovered through other methods. In this case, remote code execution flaws are especially serious because they can allow an attacker to run malicious commands on a vulnerable system from another location.
Google also found that AI-assisted vulnerability research produced fewer low-risk findings. Between January and August 2026, 39% of likely AI-discovered vulnerabilities were rated low risk under Google’s threat risk system, compared with 69% of those not linked to AI. Meanwhile Medium-risk vulnerabilities accounted for 58% of AI discoveries, compared with 28% for the wider group.
AI Is Finding the Flaws Attackers Want
The findings show how AI security tools are moving beyond simply scanning large amounts of code for obvious mistakes.
According to Google, newer autonomous security agents can follow complicated paths through software, test how different parts of a program interact and identify memory corruption or logic problems that traditional automated tools may miss.
However, the company also cautioned that the comparison does not necessarily mean AI naturally finds more dangerous bugs in every situation. Security researchers often deliberately direct these systems towards important software and high-value parts of a system, which can increase the chances of finding more serious vulnerabilities. Public records also do not consistently identify whether AI was involved in discovering a vulnerability.
Still, one recent case shows why these discoveries matter.
CVE-2026-1731, a critical vulnerability affecting BeyondTrust Remote Support and Privileged Remote Access, was identified through AI-enabled research by Hacktron AI. The flaw allowed an unauthenticated attacker to potentially execute operating system commands remotely and received a critical CVSS score of 9.9.
Google said attackers began exploiting the vulnerability within four days of its public disclosure, with five additional threat clusters observed within seven days. BeyondTrust later confirmed exploitation attempts against some internet-facing systems that had not yet been patched.
Software Vulnerability Disclosures Are Also Rising
The shift is happening while the overall number of disclosed software vulnerabilities is climbing sharply.
Google recorded 5,045 vulnerability disclosures in January 2026. By August, that number had more than doubled to 10,740, with High-risk disclosures also increasing from 131 in January to 350 in August.
But Google warned against assuming AI caused the entire increase, as changes in how vulnerabilities are automatically assigned identifiers, particularly in open-source projects, have also pushed the numbers higher.
Actual exploitation has risen too, with Google recording 141 vulnerabilities that were both disclosed and exploited between January and August 2026, already exceeding the 127 recorded throughout 2025. Yet only 0.23% of all vulnerabilities disclosed in 2026 were observed being actively exploited.
As such, for security teams, the growing number of discoveries creates another problem. Finding more vulnerabilities only helps if the most dangerous ones can be identified and fixed before attackers reach them.
And in this case, Google is recommending that companies prioritise vulnerabilities according to their real-world risk, use AI to review software before release, and automate parts of the process of finding and fixing flaws.
As AI becomes better at searching software for weaknesses, the advantage may increasingly depend on who finds the vulnerability first and how quickly it is fixed before a threat actor learns how to exploit it.
