Skip to content
← All news
4 min read

AI Tools Find Plenty of Security Flaws. Almost None of Them Get Exploited.

VulnCheck's mid-year report tracked AI-discovered vulnerabilities against real exploitation data. Anthropic's own numbers tell the same story: thousands of findings, almost none of them actually used.

AI finds thousands of security flaws. A new report says almost none get exploited.

VulnCheck's State of Exploitation report for the first half of 2026, published July 28, tracked 1,061 vulnerabilities attributed to AI-assisted discovery. Only 14 of them, 1.3 percent, have been confirmed exploited in the wild, roughly matching the overall exploitation rate for every vulnerability tracked in the same period.

Anthropic's own numbers say the same thing

Anthropic's Project Glasswing, a coalition announced in April 2026 with AWS, Apple, Cisco, Google, Microsoft, NVIDIA, and others that gives partner defenders access to an unreleased Claude model specifically to find and harden vulnerabilities, reported more than 23,000 candidate findings through its own disclosure ledger. Of those, only 126 became published CVEs, and just one has been confirmed exploited. VulnCheck also notes the ledger itself has stalled at 1,611 committed entries since launch, with more than 150 findings now past their own disclosure deadline.

The context that makes this notable

Overall CVE volume is surging, on pace to roughly double 2025's total, while the exploitation rate has stayed flat. Report author Patrick Garrity's conclusion: AI-assisted vulnerability discovery has been overhyped relative to the evidence available today. He's careful to add that this doesn't mean the risk is imaginary, just that the fear of AI mass-producing exploitable bugs has outrun what the data actually shows so far.

Why a build studio cares

This is a useful, data-backed counterweight to both the hype and the panic around AI security tooling. AI-assisted scanning is finding real things, but a flaw existing and a flaw being weaponized are still two different events, and conflating them leads to the wrong security priorities.

Next step: read The Decoder's coverage or VulnCheck's own report. If you want a clear-eyed read on where AI actually helps your security posture, write to us at hello@gattyworks.com.

AI SecurityCybersecurityAnthropicAISecurityVulnCheckAnthropicProjectGlasswingCybersecurityCVEAIforSecurityTechNewsMachineLearningArtificialIntelligence

Ready to know?

Send what you want checked or built. Fixed scope, price, and date in writing inside 24 hours, or the website or audit fee on your first project is refunded in full.

24 clock hours. Weekends included.