AI Is Finding Your Vulnerabilities First — And Exploiting Them Within 4 Days
Google Threat Intelligence Group found that AI-discovered vulnerabilities are 50% likely to enable RCE, and attackers are exploiting them within days. Here's what your vulnerability management program needs to change.

If you’ve been running vulnerability management programs for a while, you know the drill. A new CVE drops, the vendor puts out a patch timeline, you triage, prioritize, patch. You’ve got days or weeks to act before exploitation ramps up.
That timeline is collapsing.
Google Threat Intelligence Group published research on October 1, 2026 that shows attackers are exploiting AI-discovered vulnerabilities in a matter of days. Not weeks. Days.
Here’s what the data actually shows.
Google Found That AI-Discovered CVEs Get Exploited Fast
The research looked at thousands of CVE disclosures and categorized which ones were likely discovered by AI systems versus human researchers or traditional scanners. The results paint a very specific picture.
Fifty percent of AI-discovered vulnerabilities resulted in Remote Code Execution. Compare that to 26% across all other CVEs. AI is not just finding more bugs. It’s finding the ones that let attackers execute code on your systems.
One specific example: CVE-2026-1731, an unauthenticated OS command injection in BeyondTrust Privileged Remote Access. The Hacktrons AI research agent discovered it. A threat cluster exploited it within four days of public disclosure.
Four days.
That is not a comfortable number for anyone responsible for patching privileged access tools.
Why AI Finds the Hard Stuff
This is the part that matters for your defense strategy.
Vulnerabilities found by people and conventional scanners land in the moderate-to-low risk tier about half the time. AI-discovered vulnerabilities land there far less often. Google found that 58% of AI-discovered CVEs fall in the moderate tier, and exactly 50% result in RCE.
AI agents are not getting distracted by low-hanging fruit the way scanners do. They are navigating the code path to the critical flaws that actually matter for exploitation. That is a capability shift, not an incremental improvement.
What This Means for Your Vulnerability Management
You cannot treat all CVEs the same anymore.
The disclosure timeline is bifurcating. Human-discovered vulnerabilities still give you a window to respond. AI-discovered vulnerabilities are already compressing that window to days.
Here’s what your program needs to change:
Prioritize based on discovery method, not just CVSS. If a CVE is flagged as likely AI-discovered, treat it as higher priority than the CVSS score alone suggests. The exploitation probability is materially higher.
Patch AI-discovered RCEs within 72 hours, not 30 days. The data does not support waiting for the next maintenance window. These are not theoretical risks anymore.
Automate detection, not just patching. Your vulnerability scanners need to categorize AI-discovered CVEs differently. If your tooling flags a CVE as AI-discovered, it should route to an expedited response workflow automatically.
Assume the attacker knows about the vulnerability before you do. This is not a pessimistic assumption anymore. It is the baseline state described in the Google research.
The Bigger Picture
This research is one of the clearest signals yet that the attack lifecycle is accelerating. AI is making vulnerability discovery faster. It is also making exploitation faster.
The gap between discovery and compromise is no longer measured in weeks. It is measured in days.
If your vulnerability management program is still operating on the assumption that you have time to triage, prioritize, and schedule patches for every new CVE, you are already behind the curve.
Start treating AI-discovered vulnerabilities differently. Right now.
What I’m Watching
The Google research also noted that vulnerability disclosures have doubled overall as AI tools become more prevalent in security research. That is not necessarily bad. Finding vulnerabilities faster means they get fixed faster.
The problem is that the exploitation side is moving faster than the patching side.
My take: organizations that build AI-discovered CVE detection into their vulnerability management workflows within the next 90 days will have a material advantage over those that do not.
If you want to talk about how to restructure your vulnerability management program for this new reality, drop me a message. Happy to share what’s working.