Record vulnerabilities in 2026: 45,207 flaws detected by AI, but only 1.3% are exploited
Artificial intelligence is discovering software vulnerabilities at an unprecedented rate. Between January and 27 July 2026, the U.S. National Vulnerability Database (NVD) recorded 45,207 CVEs, a figure that already approaches the total for all of 2025 — which was, in turn, a record year — and that according to FIRST (Forum of Incident Response and Security Teams) could close the year at around 66,000 CVEs. However, the most revealing figure is not the quantity, but the contrast: of the 1,061 vulnerabilities discovered with AI assistance analyzed by VulnCheck, only 14 were actually exploited in real attacks, a scant 1.3%.
The paradox draws a new scenario for corporate cybersecurity: the ability to find flaws has skyrocketed, but the ability to turn them into effective attacks has not kept pace. Understanding why this is happening is key for any security officer or technical director who wants to prioritize their resources well.
AI as a mass discoverer of bugs
The leap in vulnerability discovery has a name: generative artificial intelligence. Tools such as advanced language models are being used both by security researchers and by development teams to audit code automatically. AI’s ability to analyze millions of lines of code in seconds and find suspicious patterns has doubled the rate of flaw discovery compared to 2025.
ProjectDiscovery reports that the average time from the disclosure of a vulnerability to its first exploitation has compressed drastically: from 63 days in 2018-2019 to just 5 days in 2023, and in 2026 the projection is -13 days, which means that attackers are exploiting vulnerabilities even before they become public. According to VulnCheck, 28.96% of the known exploited vulnerabilities (KEV) in 2025 were exploited the same day or before the CVE was published.
Why are the flaws found by AI almost never exploited?
The difference between finding a vulnerability and building a functional exploit remains enormous. These are the key factors that explain the gap:
Discovery outpaces weaponization. AI is improving the ability to find bugs faster than attackers can turn them into reliable exploits. Creating an exploit that works in real environments requires reverse engineering, testing, and adaptation to specific configurations.
Only a fraction is actually exploitable. According to a study by Hadrian cited in the 2026 reports, barely 0.47% of the security issues identified are actually exploitable in practice. Most are theoretical flaws that do not open viable attack vectors.
Faster patching thanks to the same AI. The same capability that allows vulnerabilities to be found also helps security teams remediate them before criminals can operationalize them. Of the 1,061 AI-assisted vulnerabilities analyzed by VulnCheck, only 126 had a CVE published at the time of the analysis.
Attackers prioritize profitable targets. The IBM X-Force Threat Intelligence Index 2026 confirms that cybercriminals continue to focus on misconfigured public applications, weak credentials, and basic security gaps, not on the latest vulnerability discovered by AI.
What this means for companies and users
For security officers, the message is twofold. On the one hand, it is reassuring: the avalanche of CVEs does not necessarily imply more real risk. But on the other, the patching window has closed drastically: when a vulnerability is exploitable, there are hours, not weeks, to respond.
The priority is no longer to find all bugs, but to identify which ones really matter and patch them fast. Companies should focus on protecting their public applications, services with authentication, and critical dependencies, rather than trying to cover the 45,000 theoretical vulnerabilities that AI might find in their systems.
The cybersecurity market is evolving accordingly. According to VulnCheck, the differentiator is no longer how many CVEs your scanner finds, but what exploitation intelligence it offers: knowing which vulnerabilities are actually being attacked in the real world. And for startups and SMEs, the lesson is clear: remediation speed has become the most important security metric of 2026.
Sources: VulnCheck State of Exploitation 2026, The Next Web, Bloomberg, ProjectDiscovery, IBM X-Force Threat Intelligence Index 2026, FIRST.






