Executive Summary
Attackers are increasingly weaponizing already-disclosed flaws rather than new zero-days, with AI tools accelerating the process. Google's Threat Intelligence Group (GTIG) reports 141 flaws exploited between January and August 2026, compared to 127 in all of 2025. Security leaders are significantly more concerned about n-days than zero-days.
Technical Analysis
The GTIG report highlights that monthly vulnerability disclosures have doubled from 5,045 in January to 10,740 in August, with a rise in the monthly exploitation rate from 10.5 per month last year to nearly 18 in 2026. This increase is largely driven by AI tools helping reduce the time it takes to write working exploits for publicly disclosed bugs. Threat actors are using Large Language Models (LLMs) and AI tools to automate analysis of differences between product versions, patches, vulnerability disclosure announcements, and Proof-of-Concept (POC) code to rapidly weaponize n-days.
How It Gets Exploited
An attacker would likely use AI tools to analyze publicly disclosed vulnerability information, patches, and POC code to rapidly develop working exploits for n-day flaws. They would then use these exploits to target vulnerable systems, potentially achieving high-risk flaw exploitation. For example, an attacker could use AI tools to identify and exploit a recently disclosed vulnerability in a widely used software, such as a high-risk flaw in the Linux kernel.
Impact Assessment
The surge in n-day attacks has significant implications for security leaders, with 38% expressing high concern about software n-day exploitation and 37% about network n-day exploitation. The number of high-risk flaw exploits has doubled from 28 in 2025 to 75 in the first eight months of 2026. This increase aligns with a surge in high-risk vulnerability disclosures, from 131 in January to 350 in August.
Recommended Actions
- Implement AI-driven vulnerability management to stay ahead of emerging threats.
- Prioritize patching and remediation of high-risk n-day flaws.
- Enhance threat intelligence capabilities to detect and respond to AI-driven attacks.
- Conduct regular security audits and risk assessments to identify vulnerable systems.
Sources
- CSO Online: "AI accelerates n-day attacks, as flaw disclosures and exploits double"