AI vulnerability exploitation: 23,019 bugs found, just 1 confirmed exploited

Artificial intelligence was supposed to unleash a wave of newly weaponizable software bugs on the internet. The numbers, at least so far, tell a quieter story. Despite the alarm surrounding AI vulnerability exploitation, a new analysis by VulnCheck finds that AI-discovered security flaws are being exploited at roughly the same modest rate as flaws found through traditional methods — challenging some of the more dramatic predictions that have circulated since large language models entered the security research field.
Key takeaways
- Anthropic’s Claude Mythos identified 23,019 potential vulnerability candidates, but only 126 have been published as CVEs and just one has been confirmed exploited in the wild.
- VulnCheck analyzed 1,061 AI-assisted vulnerabilities from Project Glasswing and the Berkeley Vulnerability Research Initiative and found only 14 (1.3%) confirmed exploited — matching the general exploitation rate.
- AI-assisted discovery increases the volume of found vulnerabilities but has not raised the proportion that attackers actually exploit.
- VulnCheck recorded 495 known exploited vulnerabilities in the first half of 2026, with CMS platforms and network edge devices as the main targets.
- AI products themselves are emerging as an attack surface, as adversaries hunt for weaknesses in the growing AI software stack.
Anthropic’s Project Glasswing: Big Numbers, Thin Exploitation Record
When Anthropic unveiled Project Glasswing in April, the announcement carried a serious warning: AI-assisted vulnerability discovery could let attackers hijack systems, disrupt operations, and steal data at a scale previously impossible. The numbers Anthropic put forward seemed to justify the concern.
… Continue reading the full article at the original source below.



