Agents

Google reports AI finds more and more dangerous software vulnerabilities

October 3, 2026 · 2 min read

a car driving down a street next to tall buildings
Timo Wielink / Unsplash

Google says AI is finding many more software vulnerabilities that are also much more dangerous, based on its own research into security flaws reported this year. The number of vulnerabilities reported monthly doubled from five thousand in January to over ten thousand in July, with nearly eleven thousand in August.

AI also finds far more dangerous vulnerabilities, Google states. Half of all AI-discovered security flaws enable code execution, compared to 26 percent of vulnerabilities found without AI. Google suggests the focus on code execution vulnerabilities may be explained by how frontier AI agents operate. AI models prove very good at finding memory corruption vulnerabilities such as buffer overflows and use-after-free, which allow code execution.

AI use appears to have no influence on zero-day flaws. In 2025, an average of eight vulnerabilities per month were observed where no update was available at the time of attack. From January through August this year, the average rose to eleven such vulnerabilities. However, the number of known vulnerabilities being exploited nearly doubled, from an average of 10.5 per month in 2025 to 18 per month from January through August this year.

Google states the actual number of AI-discovered vulnerabilities is likely much higher. Many CVE databases do not indicate whether a vulnerability was found by AI. Additionally, Google claims large cloud and SaaS providers often patch AI-discovered vulnerabilities without requesting a CVE number. Google expects the number of found and exploited vulnerabilities to increase in the short to medium term and says organizations should prepare for this.