Bỏ qua đến nội dung chính
Back to home
AI tools-ai 3 min read

AI Detects Thousands of Vulnerabilities, but Real-World Exploitation Rate Remains Low

VulnCheck research shows only 1.3% of AI-discovered security vulnerabilities are exploited in the wild, even as hackers accelerate their malware deployment speeds.

Tier 1 · sources 99% confidence Reviewed
Sources the-decoder.com

A new report from cybersecurity firm VulnCheck reveals that while artificial intelligence (AI) tools are proving highly effective at identifying security vulnerabilities, the actual rate of these vulnerabilities being exploited by hackers in the wild remains surprisingly low. In the first half of 2026, experts recorded thousands of AI-discovered flaws, yet actual attacks accounted for only a tiny fraction. This finding raises critical questions about how enterprises should allocate their cybersecurity defense resources in the AI era.

Background & Key Drivers

According to data published by VulnCheck, out of 1,061 security vulnerabilities discovered by AI in the first half of 2026, only 14 cases were associated with verified real-world attacks. This represents a mere 1.3% exploitation rate, an extremely modest figure for machine learning-driven automated vulnerability scanning. Notably, this rate aligns perfectly with the average exploitation rate of all standard vulnerabilities found through traditional methods. This suggests that while AI significantly inflates the volume of discovered bugs, it does not increase the proportion of critical, highly exploitable flaws. However, a worrying trend is that the median time for hackers to develop and deploy exploits has shortened significantly, dropping from 120 days to just 80 days. This compressed window forces patch management teams to act much faster to secure systems before exploits emerge.

Technical Analysis & Technology

On the technology front, vulnerability-detection AI models typically rely on static application security testing (SAST) combined with specialized large language models (LLMs). Automated scanning capabilities allow AI to rapidly parse millions of lines of code to identify common bug patterns, such as buffer overflows or command injections. However, the most significant technical hurdle currently is that AI often generates high volumes of false positives or identifies 'theoretical' flaws that are extremely difficult to exploit in real-world production environments. For a vulnerability to pose an actual threat, attackers must construct a complete exploit chain capable of bypassing external defense layers. Therefore, AI flagging a long list of weaknesses does not mean the entire system is on the verge of collapse.

Expert Insights & Perspectives

Analysts at VulnCheck suggest that the cybersecurity community should not panic over the influx of 'AI-discovered vulnerabilities.' Overemphasizing raw alerts generated by AI can overwhelm system administrators and security operations center (SOC) analysts. Instead, enterprises should focus on prioritizing vulnerabilities based on real-world impact and threat intelligence reports. Effective defense lies in intelligent triage rather than trying to patch every minor flaw pointed out by AI.

Implications & Future Outlook

The data from VulnCheck provides a more realistic, less hyped perspective on the role of AI in both cyber defense and offense. In the future, as AI models become more sophisticated, the boundary between detecting a theoretical bug and automatically generating a working exploit may blur. For Vietnamese enterprises, the key takeaway is the need to combine AI scanning tools with manual risk assessments conducted by experienced security professionals. Preparing for a tighter patching cycle (under 80 days) will be crucial to safeguarding critical digital infrastructures against increasingly agile threat actors.