Wednesday, 30 September 2026

Where technology leaders come to think out loud

ColumnCybersecurity

Double the CVEs: patching everything is no longer a security strategy

Google’s threat intelligence group says monthly vulnerability disclosures doubled between January and August. But only about one in 431 was seen exploited, and teams that still try to patch everything risk being slowest on the flaws that matter

VETTDD Cybersecurity section card
Image: VETTDD
In brief
  • GTIG says exploitation growth comes mainly from fast weaponization of n-days that already have a patch, which makes fix speed the deciding factor.
  • Half of the flaws GTIG identified as likely AI-discovered led to remote code execution, against 26% of the rest.
  • Edge and security appliances made up 14% of exploited flaws, so fix-time targets should start with the internet-facing estate.

On 30 September Google Threat Intelligence Group (GTIG) published its analysis of software vulnerabilities disclosed between January 2025 and August 2026. The number that will reach boardrooms is the volume: disclosures per month rose from 5,045 in January 2026 to 10,740 in August, according to the report. Google sells threat intelligence and security services through Google Cloud and Mandiant, so this is a vendor analyzing its own data. The figures are global, with no UK breakdown.

Exploitation rose too, though from a far smaller base. GTIG counted 141 distinct vulnerabilities disclosed and exploited from January to August, more than the 127 it recorded for the whole of 2025. That is an average of 18 a month, up from 10.5 a month in 2025. Yet only 0.23% of this year’s disclosures, roughly one in 431, were seen exploited in the wild.

Those two figures pull in opposite directions. The queue of things to patch has doubled in eight months. The share that attackers actually use has stayed tiny. A security team that tries to work through the whole queue faster, with the same people, will spend most of its effort on flaws nobody exploits.

The report’s own recommendation is that organizations “must transition from unprioritized mass-patching to threat-intelligence-driven triage”. That is the right call, and it has a consequence CISOs should put plainly to their boards: patch coverage is no longer a useful measure of risk. The measure that matters is how quickly the exposed and exploited flaws get fixed.

Where the growth really is

Some of the volume is inflation. GTIG notes that vulnerabilities with “Linux Kernel” in the description alone generated about 5,000 Common Vulnerabilities and Exposures (CVE) records between January and August, with no exploited zero-days observed among them. Vendor release cycles add spikes: in August alone, Oracle’s quarterly patch update and Linux kernel network driver advisories contributed 128 high-risk vulnerabilities, nearly 37% of that month’s high-risk disclosures.

The rise in exploitation is also narrower than it looks. Zero-day exploitation grew only from an average of eight a month in 2025 to 11 a month in 2026. GTIG suggests the main source of growth has been the rapid weaponization of n-days: vulnerabilities that have already been disclosed and patched. It says it is possible that attackers are using AI tools to automate the analysis of patches, disclosures and proof-of-concept code to build those exploits. Exploitation of flaws GTIG rates high-risk rose from 28 in 2025 to 75 in the first eight months of 2026.

Put plainly, the fastest-growing danger is a flaw for which a fix already exists. That is a speed problem for defenders, not a discovery problem.

AI finds the flaws that hurt

The report also looks at who is finding the bugs. Of the vulnerabilities GTIG could identify as likely discovered by AI, exactly half led to remote code execution (RCE), against 26% of those not found by AI. Some 58% of the AI-found flaws were rated medium risk, against 28% of the rest. GTIG cautions that public data undercounts AI discovery, because CVE records carry no standard tag for it.

Its clearest example is CVE-2026-1731, an unauthenticated command injection flaw in BeyondTrust’s Privileged Remote Access and Remote Support products, found autonomously by Hacktron AI’s research agent. According to the report, one threat cluster was exploiting it within four days of public disclosure and five more within seven days, with activity that included privilege escalation and data exfiltration. A monthly patch cycle would have left that door open for weeks.

Kelli Vanderlee, one of the report’s three authors, said that for flaws GTIG rates high-risk, exploitation “can typically be done on a wide scale”, according to The Record. AI-found flaws skew toward the higher ratings, and exploitation of high-risk flaws has more than doubled.

Measure the edge, not the backlog

Where attackers go is just as clear. Vulnerabilities in edge and security appliances made up 14% of those exploited from January to August, and enterprise directory and collaboration systems 11%, the report says. More than 65% of the edge flaws exploited in that period were rated high or critical under GTIG’s own risk ratings, which are not Common Vulnerability Scoring System (CVSS) scores. GTIG says attackers are going after unauthenticated public management interfaces to exploit blind spots in endpoint detection and response (EDR) agents.

That points to a different set of numbers for CISOs to own. Keep a live inventory of internet-facing and edge assets, security appliances included, with a named owner for each. Set a fix time in days for any known-exploited flaw on that estate, and track it. Rank the rest of the queue by exploitation intelligence rather than by severity score alone. Treat any product that exposes a management interface to the internet as the first place to look, not the last.

Boards should change their question too. Asking what share of vulnerabilities is patched invites a flattering answer when more than 10,000 were disclosed in each of July and August. The better question is how many days the organization’s exposed systems stayed open to a flaw that attackers were already using.

GTIG expects discovery and exploitation to keep growing in the short to medium term. Security teams that measure themselves on the backlog will fall further behind every month. Teams that measure the edge, in days, at least know where the fight is.

AdvertisementZoomInfo

Get The VETTDD BriefingThe week in the technology channel, every week.

Subscribe free
Sources
  1. Google Threat Intelligence Group (Robin Grunewald, Supriya Mazumdar, Kelli Vanderlee), “Vulnerability Discovery and Exploitation Trends in the AI Era”, report (Google Cloud blog), 30 September 2026. https://cloud.google.com/blog/topics/threat-intelligence/vulnerability-discovery-and-exploitation-trends-in-the-ai-era
  2. The Record (Recorded Future News), “Google: Vulnerability disclosures double to 10,000 per month as AI fuels exploitation”, news article, 30 September 2026. https://therecord.media/google-vulnerabilities-cyberattacks-ai
About the author

Editor

The VETTDD editorial desk. Interviews, analysis, columns and news on the decisions shaping UK B2B technology.

More from Editor →