AI-assisted security tools identified 1,061 vulnerabilities in the first half of 2026, but only 14 were confirmed to be exploited, according to VulnCheck. This exploitation rate of 1.3% matches the overall average for vulnerabilities. Anthropic's Project Glasswing contributed over 23,000 findings, leading to 126 published entries and one confirmed attack. Despite the high volume of findings, the rate at which vulnerabilities are exploited is increasing.

Half of all flaws now see their first confirmed exploitation within 80 days of disclosure, down from 120 days the previous year. About 200 vulnerabilities were attacked within a month, even as the total number of reported vulnerabilities continues to rise. The median time from vulnerability disclosure to first confirmed exploit dropped from 120 to 80 days. Website content management systems are the most targeted, making up a third of all cases.

Garrity also highlights AI products themselves as a growing attack surface, including model-building tools and agent interfaces. The sheer volume of findings, in other words, tells defenders very little about actual risk.