AI is helping researchers surface a growing number of security flaws, but the number of findings is not the same as the number of real-world attacks. A VulnCheck count from Patrick Garrity shows that, in the first half of 2026, AI-assisted vulnerability discovery produced many entries while confirmed exploitation remained rare.
AI is finding many flaws, but few are exploited
For the first half of 2026, Patrick Garrity counts 1,061 vulnerabilities traced to AI-assisted discovery. Of those, fourteen showed confirmed exploitation. That equals 1.3%, which the source describes as roughly the same rate as vulnerabilities overall.
The point is not that AI-generated findings are meaningless. It is that volume alone can mislead defenders. A long list of vulnerabilities may look urgent, but the source indicates that only a small share of AI-assisted discoveries have been confirmed in attacks.
That distinction matters because security work is always a prioritization problem. Teams need to know which flaws are likely to become operational risk, not only which flaws exist. If AI tools increase the number of reported vulnerabilities without changing the exploitation rate, defenders may face more noise without a clear signal about what attackers will actually use.
Project Glasswing shows the scale problem
Anthropic's Project Glasswing is the clearest example in the source. It produced more than 23,000 findings. Those findings led to 126 published entries and a single confirmed attack.
That path from findings to published entries to confirmed exploitation shows why raw AI output needs careful interpretation. A finding can be useful, but it does not automatically become a published vulnerability. A published entry can be important, but it does not automatically become an exploited flaw.
For defenders, the lesson is practical: AI vulnerability discovery can expand visibility, but it does not remove the need for judgment. The source does not say that AI findings should be ignored. It shows that organizations should avoid treating every AI-assisted result as equal in urgency.
Exploitation is happening faster
The exploitation rate may be low, but the timing is changing. Half of all flaws now see their first confirmed exploitation within 80 days of disclosure, down from 120 days the year before. About 200 were attacked within a month.
That faster timeline is important because it compresses the window for response. Even if only a minority of vulnerabilities are exploited, the ones that do attract attackers can move quickly from disclosure to confirmed attack.
The source also notes that the total number of reported vulnerabilities keeps climbing. That creates a difficult combination: more reported flaws, faster exploitation for many of the flaws that do get attacked, and no simple way to infer real risk from volume alone.
- AI-assisted discovery increases the number of security flaws being surfaced.
- Confirmed exploitation remains rare among those AI-linked findings.
- Attackers are moving faster against flaws that do become targets.
- The total number of reported vulnerabilities continues to rise.
Where attacks are concentrating
Website content management systems take the most hits, accounting for a third of all cases. That gives defenders one concrete area to watch closely, based on the source. It also reinforces that attacker behavior is not evenly distributed across every class of software.
Garrity also flags AI products themselves as a growing attack surface. The source specifically names model-building tools and agent interfaces. As more AI systems become part of software workflows, the tools used to build, connect, and operate them can become part of the risk picture.
This does not mean every AI product is under attack, and the source does not provide a broader list of affected systems. It does mean that AI is present on both sides of the vulnerability story: it is helping find flaws, and AI products themselves are becoming places defenders need to examine.
The useful takeaway for defenders
The most important finding is that AI-generated volume is not a reliable stand-in for risk. VulnCheck's count shows a large number of AI-assisted discoveries, but only fourteen confirmed exploited cases among 1,061 vulnerabilities in the first half of 2026.
At the same time, defenders cannot relax. Exploitation is landing faster, with half of all flaws seeing first confirmed exploitation within 80 days of disclosure and about 200 attacked within a month. That means prioritization has to consider both likelihood and speed.
AI vulnerability discovery may keep adding to the workload. The source shows why the response should be disciplined: separate findings from published entries, separate published entries from confirmed exploitation, and avoid treating the size of the queue as the same thing as the size of the threat.