Finding more bugs is not the same as handing attackers a free exploit farm. On July 28, 2026, VulnCheck published State of Exploitation 1H-2026: of 1,061 publicly attributed AI-assisted vulnerability discoveries, only 14 (1.3%) landed in Known Exploited Vulnerability (KEV) status — about the same rate as vulns overall. The Register framed it bluntly: AI-found bugs aren’t proving any easier to exploit despite the hype.
That punches a hole in the loudest reading of Anthropic’s Project Glasswing launch — without claiming the risk is fake.
TL;DR
| Question | Answer |
|---|---|
| AI-assisted finds → KEV? | 14 / 1,061 = 1.3% |
| Baseline? | Roughly matches all-vuln exploit rate in 1H 2026 |
| Glasswing candidates | 23,019 reported findings |
| → published CVEs | ~126 |
| → confirmed wild exploit | 1 (CVE-2026-26980) |
| 1H 2026 KEVs total | 495 |
| CVE → KEV median | 120 → 80 days (2025 → 1H 2026) |
| Still hottest targets | CMS (~⅓ of KEVs), network edge, rising AI stack |
What people ask after the Register headline
“So Mythos / Glasswing was marketing?”
Separate three claims:
- Models can find serious bugs (including old/subtle classes) — still supported by Anthropic’s public case studies and explainx.ai’s Glasswing coverage.
- Volume of candidates will explode — supported (and now visible in CVE issuance growth).
- AI-found bugs are disproportionately weaponized — not supported by VulnCheck’s 1H 2026 correlation with KEV.
Patrick Garrity’s line (paraphrased from the report and Register): AI discovery has value for attackers and defenders; the data does not show AI-found vulns are inherently more likely to be exploited than traditional finds. Volume up; share exploited flat.
“Why only 126 CVEs from 23k findings?”
Candidate ≠ CVE. Triage, duplicate collapse, vendor rejection, and stalled disclosure all shrink the public set. VulnCheck’s sharper jab: Anthropic’s disclosure ledger barely moved past the original ~1,611 committed entries at launch, with findings past stated deadlines still unpublished. That is a process / transparency critique as much as a capability critique.
“Could exploitation just be delayed?”
Yes — and VulnCheck says so. Many CVEs become KEVs months later; 1H 2026 cohorts are immature. Early exploitation (~200 CVEs to KEV within 31 days) is steady, not exploding with CVE volume. Watch 2H 2026 as Glasswing / Daybreak / MDASH-style programs age.
The Glasswing scoreboard (VulnCheck’s cut)
| Metric | Figure |
|---|---|
| Mythos / Glasswing findings claimed | 23,019 |
| Ledger growth since launch | Stalled near ~1,611 committed entries (per VulnCheck) |
| Published as CVEs (tracked) | 126 |
| Confirmed exploited in wild | 1 — CVE-2026-26980 |
| Seen on VulnCheck canaries | Yes (for that one) |
This does not erase Mythos crypto research or autonomous bug-finding demos. It reframes cyber offense hype: discovery ≠ exploitation pipeline.
Broader 1H 2026 exploitation context
AI is not the only story in the report — and that is the point for SOC prioritization.
| Signal | Detail |
|---|---|
| KEVs in 1H 2026 | 495 |
| Exploited on/before CVE day | 23.43% (down from 28.93% in 2025) |
| Median CVE → KEV | 80 days (from 120 in 2025) |
| KEV/CVE ratio | Down to ~1.4% as CVE volume grew ~45% vs prior half |
| CMS share of KEVs | ~⅓ — WordPress plugins + Drupal/Ghost/etc. |
| Network edge | Still heavily targeted (Cisco, Palo Alto, Fortinet, …) |
| AI products as targets | Model builders, scalers, gateways, agents, workflow automation |
Example called out: LangFlow exploitation via CVE-2026-0769 / CVE-2026-5027 on canaries — credential harvest (OpenAI/Claude-class keys), miners, lateral movement attempts. Neither was on CISA KEV at report time. Attackers are hunting the AI software stack, not only using AI to hunt classic stacks.
Microsoft Patch Tuesday volume (CyberScoop note: July record 622 vulns) is the defender-side twin of the same volume shock.
How to read this next to other July cyber news
Same week / month on explainx.ai:
| Story | Lesson |
|---|---|
| Glasswing / Mythos cyber | Capability narrative: models find deep bugs |
| This VulnCheck cut | Outcome narrative: exploit share not special (yet) |
| Codex Security CLI | Defenders get open agentic scanners |
| HF agent intrusion | Agents as attackers against AI platforms |
| Copilot Word AI worm | Integrity/XPIA class ≠ CVE volume story |
| Pacing the Frontier | Industry asks for tools to pace automated R&D |
| Sakana Fugu-Cyber | Localized harness + humans still the product |
Garrity’s closer matches explainx.ai’s default stance: overhyped relative to evidence today; risk not imaginary; watch maturity.
What builders and CISOs should change Monday
- Stop ranking by “AI-found” badge. Rank by exposure + exploit evidence + blast radius.
- Fund triage, not only scanners — 23k candidates without disclosure velocity is noise.
- CMS + edge patching remains the exploitation bulk; don’t let AI headlines steal that budget.
- Inventory AI gateways/agents as internet-facing apps (LangFlow-class lessons).
- Use frontier models for defense discovery while access is asymmetric — VulnCheck’s own conclusion leans defender-advantage if producers remediate.
- Track disclosure SLAs for vendors (and labs) that publish candidate ledgers.
- Revisit BOD-style urgency — 80-day median to KEV is why three-day remediation guidance exists for high-risk cases.
Honest caveats (so you don’t over-correct)
- Attribution noise: “AI-assisted” tags depend on public credit; silent AI use is invisible.
- Under-counting Glasswing impact: private vendor fixes never become CVEs.
- Canary ≠ global prevalence: four AI-discovered hits on VulnCheck canaries are signal, not a census.
- Access gates: Mythos/Glasswing-class models were not free-for-all in 1H 2026 — wider access could change rates.
- Cryptanalysis ≠ web RCE: Mythos HAWK/AES work is a different risk surface than KEV charts.
How VulnCheck built the AI-discovery set
Methodology matters when headlines say “AI vulns aren’t dangerous.”
- Track disclosures attributed to Anthropic / Glasswing.
- Add the Berkeley Vulnerability Research Initiative stream.
- Consolidate to 1,061 attributed AI-assisted finds.
- Correlate with VulnCheck KEV (not only CISA KEV).
- Optionally check canaries (real vulnerable hosts VulnCheck runs).
That pipeline answers a narrow question: among publicly attributed AI-assisted finds, how often do we later see confirmed wild exploitation? It does not answer: how many AI finds were silently fixed, how many attackers use private models without credit, or whether 2H 2026 changes the curve when more frontier cyber access ships.
CyberScoop’s reminder fits: Glasswing launched in April; Microsoft MDASH and OpenAI Daybreak in May — none ran for the full half-year. Treat 1.3% as an early rate card, not a permanent law of nature.
Discovery volume vs exploit volume (the ratio story)
VulnCheck’s wider charts show CVE issuance outrunning KEV growth: KEV-to-CVE ratio drifted toward ~1.4% in 1H 2026 while CVE volume jumped ~45% half-over-half. Early exploitation counts (~200 CVEs to KEV within 31 days) look like 2024/2025 — steady absolute early hits, smaller share of a bigger CVE pile.
That is the defender’s double bind: more tickets in the queue, similar early exploit absolute numbers, faster median time-to-KEV for those that do get hit. AI discovery is one driver of the queue; WordPress plugin CVE industrialization is another. Neither automatically means every new CVE is a ransomware event.
Glasswing hype vs Daybreak / Codex Security reality
Anthropic’s April narrative emphasized dual-use danger: attackers could use similar capability to hijack systems. VulnCheck’s July cut says: public exploit evidence for that specific discovery wave is thin so far.
OpenAI’s track in the same season is different product shape — gated cyber agents and now an open Codex Security CLI for defenders. explainx.ai’s Daybreak guide is the defender tooling story; this VulnCheck post is the outcome metrics story. You need both: capability demos without KEV correlation become lore; KEV charts without capability context miss why CVE volume is rising.
Sakana’s Fugu-Cyber pitch — frontier models plus localized harness plus humans — is consistent with VulnCheck’s “give defenders advanced models” conclusion. Finding is cheapening; verification and patch shipping remain the bottleneck (same theme as Mythos cryptanalysis needing human validation).
Operator FAQ for the all-hands deck
Q: Do we stop using AI bug finders?
No. Use them to increase coverage, then measure mean time to triage and patch.
Q: Do we panic-patch every Glasswing-adjacent CVE first?
No. Panic-patch from exposure + KEV/canary evidence, same as always.
Q: Why did Anthropic scare us then?
Because dual-use capability demos are real; because N-day windows compress when exploit synthesis is cheap; because disclosure volume can overwhelm vendors. Scare without follow-through ledger updates is what VulnCheck is dinging.
Q: What’s the one metric to watch next?
Share of AI-attributed finds that become KEV over trailing 12 months as access widens — plus whether AI-product KEVs keep climbing.
Q: How does this interact with “Pacing the Frontier”?
Employees asking for pacing tools are arguing about automated R&D acceleration. VulnCheck is arguing about exploitation outcomes so far. Both can be true: research automates faster while wild exploit share on AI-tagged CVEs stays boring — until it doesn’t.
Numbers cheat sheet for briefings
AI-assisted attributed finds (Glasswing + Berkeley): 1,061
Confirmed exploited (KEV): 14 (1.3%)
Glasswing findings claimed: 23,019
Published CVEs from that program (tracked): ~126
Wild exploit from that set: 1 (CVE-2026-26980)
1H 2026 KEVs overall: 495
Median CVE→KEV: 80 days
CMS share of KEVs: ~33%
Use that slide. Do not replace it with “AI changed nothing” or “AI ended infosec.”
Related on explainx.ai
- Claude Mythos Preview + Project Glasswing
- Mythos cryptographic weaknesses (HAWK / AES)
- OpenAI Daybreak / Codex Security
- Codex Security CLI open-sourced
- Sakana Fugu-Cyber benchmarks
- Zhipu matches Mythos on security bugs
- Hugging Face agent intrusion timeline
- Pacing the Frontier letter
- Copilot for Word document AI worm
Official / primary
- VulnCheck — State of Exploitation 1H-2026
- The Register — AI-found bugs aren’t easier to exploit
- CyberScoop — threat level has not changed
- Anthropic — Mythos / Glasswing cybersecurity (April 2026)
Figures reflect VulnCheck’s July 28, 2026 report and contemporaneous Register/CyberScoop coverage. KEV status and Glasswing ledger counts move — re-check VulnCheck and Anthropic before you cite them in an audit.
