AI Tools Find Plenty of Security Flaws. Almost None of Them Get Exploited.
VulnCheck's mid-year report tracked AI-discovered vulnerabilities against real exploitation data. Anthropic's own numbers tell the same story: thousands of findings, almost none of them actually used.
AI finds thousands of security flaws. A new report says almost none get exploited.
VulnCheck's State of Exploitation report for the first half of 2026, published July 28, tracked 1,061 vulnerabilities attributed to AI-assisted discovery. Only 14 of them, 1.3 percent, have been confirmed exploited in the wild, roughly matching the overall exploitation rate for every vulnerability tracked in the same period.
Anthropic's own numbers say the same thing
Anthropic's Project Glasswing, a coalition announced in April 2026 with AWS, Apple, Cisco, Google, Microsoft, NVIDIA, and others that gives partner defenders access to an unreleased Claude model specifically to find and harden vulnerabilities, reported more than 23,000 candidate findings through its own disclosure ledger. Of those, only 126 became published CVEs, and just one has been confirmed exploited. VulnCheck also notes the ledger itself has stalled at 1,611 committed entries since launch, with more than 150 findings now past their own disclosure deadline.
The context that makes this notable
Overall CVE volume is surging, on pace to roughly double 2025's total, while the exploitation rate has stayed flat. Report author Patrick Garrity's conclusion: AI-assisted vulnerability discovery has been overhyped relative to the evidence available today. He's careful to add that this doesn't mean the risk is imaginary, just that the fear of AI mass-producing exploitable bugs has outrun what the data actually shows so far.
Why a build studio cares
This is a useful, data-backed counterweight to both the hype and the panic around AI security tooling. AI-assisted scanning is finding real things, but a flaw existing and a flaw being weaponized are still two different events, and conflating them leads to the wrong security priorities.
Next step: read The Decoder's coverage or VulnCheck's own report. If you want a clear-eyed read on where AI actually helps your security posture, write to us at hello@gattyworks.com.