Google Threat Intelligence Group reports that AI is accelerating vulnerability disclosure and exploitation, with CVE disclosures, in-the-wild exploitation, and zero-day activity all rising through 2026. The report also shows AI is helping discover more high-impact flaws and that attackers are increasingly targeting AI/LLM infrastructure and exposed enterprise middleware. #CVE #GTIG #BeyondTrustPRA #Langflow #LiteLLM #Flowise #LangChain
Keypoints
- Vulnerability disclosures doubled in 2026, rising from 5,045 in January to 10,740 in August.
- In-the-wild exploitation also increased, with 141 distinct vulnerabilities exploited from January to August 2026, exceeding the full-year 2025 total.
- Zero-day exploitation rose only slightly overall, but jumped to 22 in August 2026.
- AI-assisted discovery appears to surface proportionally fewer low-risk issues and more medium- and high-risk vulnerabilities, including more RCE-prone flaws.
- High-Risk disclosures were driven partly by large vendor disclosure cycles, especially TOTOLINK and Oracle/Linux.
- Attackers are concentrating on edge appliances, security appliances, and enterprise services for initial access and follow-on compromise.
- AI/LLM infrastructure is an emerging target, with major exposure in orchestration frameworks, inference stacks, web apps, and AI gateways.
MITRE Techniques
- [T1190] Exploit Public-Facing Application â Threat actors targeted exposed enterprise and AI middleware services and unauthenticated endpoints for initial access; cited as exploiting public management interfaces and exposed middleware (âunauthenticated public management interfacesâ, âexposed middlewareâ).
- [T1068] Exploitation for Privilege Escalation â Post-exploitation activity included privilege escalation after initial compromise of vulnerabilities such as CVE-2026-1731 (âpost-exploitation activities, including privilege escalationâ).
- [T1059] Command and Scripting Interpreter â Several flaws enabled command injection or Python code execution, allowing adversaries to run commands on the host (âOS command injectionâ, âPython code injection via exec()â).
- [T1195] Supply Chain Compromise â The report describes vulnerabilities in software ecosystems, vendor disclosure cycles, and AI/LLM stack components that can be abused before downstream deployment (âsoftware or services to other enterprises and consumersâ).
- [T1021] Remote Services â Threat activity involved compromise of remote support and privileged access services, enabling remote interaction with targeted systems (âBeyondTrust Privileged Remote Access (PRA) and Remote Supportâ).
- [T1005] Data from Local System â Attackers were observed stealing API credentials and exfiltrating data from compromised systems (âAPI credential theftâ, âdata exfiltrationâ).
- [T1074] Data Staged â The report notes theft of credentials and private prompt streams from AI gateways, implying collection of sensitive data before exfiltration (âprivate prompt streams containing personally identifiable informationâ).
- [T1105] Ingress Tool Transfer â Secondary payloads such as SNOWLIGHT and SPARKRAT were dropped onto compromised systems (âdropping secondary payloads including SNOWLIGHT, SPARKRATâ).
- [T1053] Scheduled Task/Job â One Langflow issue allowed remote actors to drop cron jobs onto hosts, indicating scheduled execution persistence (âdrop unauthorized files (e.g., cron jobs)â).
- [T1106] Native API â Exploitation of unauthenticated administrative APIs and AI platform endpoints was used as a direct entry path (âUnauthenticated Administrative APIsâ).
- [T1211] Exploitation for Defense Evasion â AI gateways and edge appliances were abused to bypass perimeter controls and EDR blind spots (âbypass perimeter firewallsâ, âenterprise EDR agent blind spotsâ).
Indicators of Compromise
- [CVE identifiers] Vulnerabilities and exploited issues discussed throughout the report â CVE-2026-1731, CVE-2026-42271, and other CVEs including CVE-2026-5027 and CVE-2025-3248.
- [Product / vendor names] Affected software and platforms used as targets or disclosure sources â BeyondTrust Privileged Remote Access (PRA), Langflow, and BerriAI LiteLLM.
- [File paths / endpoints] Exploited request locations and handlers â POST /mcp-rest/test/connection, POST /api/v2/files, and /api/v1/validate/code.
- [Malware / payload names] Secondary payloads observed after exploitation â SNOWLIGHT, SPARKRAT, and cryptominers.
- [Technology / framework names] AI stack components and exposed services associated with vulnerabilities â Flowise, LangChain, vLLM, Triton, and Ollama.
- [Ports / network indicators] No specific IPs, domains, or hashes were provided in the article.