Vulnerability Discovery and Exploitation Trends in the AI Era

Vulnerability Discovery and Exploitation Trends in the AI Era
Google Threat Intelligence Group reports that AI is accelerating vulnerability disclosure and exploitation, with CVE disclosures, in-the-wild exploitation, and zero-day activity all rising through 2026. The report also shows AI is helping discover more high-impact flaws and that attackers are increasingly targeting AI/LLM infrastructure and exposed enterprise middleware. #CVE #GTIG #BeyondTrustPRA #Langflow #LiteLLM #Flowise #LangChain

Keypoints

  • Vulnerability disclosures doubled in 2026, rising from 5,045 in January to 10,740 in August.
  • In-the-wild exploitation also increased, with 141 distinct vulnerabilities exploited from January to August 2026, exceeding the full-year 2025 total.
  • Zero-day exploitation rose only slightly overall, but jumped to 22 in August 2026.
  • AI-assisted discovery appears to surface proportionally fewer low-risk issues and more medium- and high-risk vulnerabilities, including more RCE-prone flaws.
  • High-Risk disclosures were driven partly by large vendor disclosure cycles, especially TOTOLINK and Oracle/Linux.
  • Attackers are concentrating on edge appliances, security appliances, and enterprise services for initial access and follow-on compromise.
  • AI/LLM infrastructure is an emerging target, with major exposure in orchestration frameworks, inference stacks, web apps, and AI gateways.

MITRE Techniques

  • [T1190] Exploit Public-Facing Application – Threat actors targeted exposed enterprise and AI middleware services and unauthenticated endpoints for initial access; cited as exploiting public management interfaces and exposed middleware (‘unauthenticated public management interfaces’, ‘exposed middleware’).
  • [T1068] Exploitation for Privilege Escalation – Post-exploitation activity included privilege escalation after initial compromise of vulnerabilities such as CVE-2026-1731 (‘post-exploitation activities, including privilege escalation’).
  • [T1059] Command and Scripting Interpreter – Several flaws enabled command injection or Python code execution, allowing adversaries to run commands on the host (‘OS command injection’, ‘Python code injection via exec()’).
  • [T1195] Supply Chain Compromise – The report describes vulnerabilities in software ecosystems, vendor disclosure cycles, and AI/LLM stack components that can be abused before downstream deployment (‘software or services to other enterprises and consumers’).
  • [T1021] Remote Services – Threat activity involved compromise of remote support and privileged access services, enabling remote interaction with targeted systems (‘BeyondTrust Privileged Remote Access (PRA) and Remote Support’).
  • [T1005] Data from Local System – Attackers were observed stealing API credentials and exfiltrating data from compromised systems (‘API credential theft’, ‘data exfiltration’).
  • [T1074] Data Staged – The report notes theft of credentials and private prompt streams from AI gateways, implying collection of sensitive data before exfiltration (‘private prompt streams containing personally identifiable information’).
  • [T1105] Ingress Tool Transfer – Secondary payloads such as SNOWLIGHT and SPARKRAT were dropped onto compromised systems (‘dropping secondary payloads including SNOWLIGHT, SPARKRAT’).
  • [T1053] Scheduled Task/Job – One Langflow issue allowed remote actors to drop cron jobs onto hosts, indicating scheduled execution persistence (‘drop unauthorized files (e.g., cron jobs)’).
  • [T1106] Native API – Exploitation of unauthenticated administrative APIs and AI platform endpoints was used as a direct entry path (‘Unauthenticated Administrative APIs’).
  • [T1211] Exploitation for Defense Evasion – AI gateways and edge appliances were abused to bypass perimeter controls and EDR blind spots (‘bypass perimeter firewalls’, ‘enterprise EDR agent blind spots’).

Indicators of Compromise

  • [CVE identifiers] Vulnerabilities and exploited issues discussed throughout the report – CVE-2026-1731, CVE-2026-42271, and other CVEs including CVE-2026-5027 and CVE-2025-3248.
  • [Product / vendor names] Affected software and platforms used as targets or disclosure sources – BeyondTrust Privileged Remote Access (PRA), Langflow, and BerriAI LiteLLM.
  • [File paths / endpoints] Exploited request locations and handlers – POST /mcp-rest/test/connection, POST /api/v2/files, and /api/v1/validate/code.
  • [Malware / payload names] Secondary payloads observed after exploitation – SNOWLIGHT, SPARKRAT, and cryptominers.
  • [Technology / framework names] AI stack components and exposed services associated with vulnerabilities – Flowise, LangChain, vLLM, Triton, and Ollama.
  • [Ports / network indicators] No specific IPs, domains, or hashes were provided in the article.


Read more: https://cloud.google.com/blog/topics/threat-intelligence/vulnerability-discovery-and-exploitation-trends-in-the-ai-era/