AI-driven vulnerability discovery is the use of machine learning and large language models to find software flaws faster than human researchers could. In a report published on September 30, 2026, the Google Threat Intelligence Group (GTIG) documented what that looks like in practice: monthly CVE disclosures roughly doubled in 2026, from 5,045 in January to 10,740 in August. High-risk disclosures grew even faster, from 131 in January to 350 in August, an increase of about 167%.
Why does this matter to an enterprise? Because the volume of vulnerabilities your teams must triage has doubled while the number of people and maintenance windows has not. Every new CVE is a decision: does it affect us, is it exposed, is it being exploited, and what do we do first?
The quality of those flaws is changing too. GTIG found that about half of AI-discovered vulnerabilities allow remote code execution, compared with 26% of flaws found by other methods. Only 39% of AI-discovered bugs are rated Low risk, against 69% for the rest. In plain terms, AI is not just finding more bugs, it is finding the ones attackers want. For organizations that depend on a managed cybersecurity service with 24/7 SOC, SIEM and MDR, this shift changes what good looks like: prioritization and speed now matter more than raw patch counts.
The second half of the GTIG finding is about attackers. Google tracked 141 distinct exploited vulnerabilities between January and August 2026, already more than the 127 seen in all of 2025. The monthly average rose from 10.5 to 18. Zero-days, flaws exploited before a fix exists, averaged 11 per month versus 8 last year and made up 62% of exploited vulnerabilities. High-risk flaws exploited in the wild jumped from 28 in 2025 to 75 in the first eight months of 2026.
Speed is the sharpest edge. One example in the report, CVE-2026-1731 in BeyondTrust software, was exploited by one threat cluster within four days of disclosure and by five more within seven days. A monthly patch cycle simply cannot compete with that clock.
Does that mean everything must be patched immediately? No, and this is the most useful number in the report: only 0.23% of disclosed vulnerabilities, about 1 in 431, are exploited. The challenge is therefore not patching more, it is knowing which 1 in 431 is the one on your network, on an internet-facing system, in a product your business depends on. That is a visibility and prioritization problem before it is a patching problem.
What should an enterprise change in 2026? Replace calendar-driven patching with a risk-driven model built on the following steps.
Know your assets. Maintain a live inventory of servers, endpoints, network appliances, SaaS and open-source components, including who owns each one. You cannot rank risk on systems you cannot see.
Prioritize by exposure and exploitation, not by score alone. Combine severity with signals such as presence on CISA's Known Exploited Vulnerabilities list, internet exposure, availability of public exploit code and the business criticality of the asset.
Put edge and identity first. VPNs, firewalls, SD-WAN controllers, email gateways and remote-access tools are repeatedly the first targets because they are reachable without a password. They deserve shorter patch windows than internal workstations.
Pre-approve emergency changes. Define in advance who can authorize an out-of-cycle patch, what testing is mandatory and how rollback works, so a four-day exploit window does not become a three-week approval chain.
Use compensating controls while you patch. Restrict management interfaces, segment critical systems, disable unused features and apply virtual patching or tighter access rules until the fix is live.
Hunt, don't just wait. Feed new indicators of compromise into your SIEM and EDR, and assume that exploitation can precede the advisory.
Teams that cannot staff this around the clock can rely on managed IT services for asset inventory, patch orchestration, change control and backup, turning an urgent advisory into a repeatable procedure.
Why change an approach that has worked for years? Because the volume and severity trends in the GTIG data make the old approach increasingly expensive and unreliable.
Lower breach likelihood. Focusing first on the small fraction of vulnerabilities that are actually exploited, and on the systems that are actually exposed, closes the doors attackers are using rather than the ones they ignore.
Efficient use of scarce talent. With disclosures doubling, no security team can chase every CVE. Prioritization lets engineers spend time on the 0.23% that matter instead of burning out on the 99.77% that do not.
Shorter mean time to remediate. Pre-approved emergency windows, tested rollbacks and clear ownership shrink the gap between advisory and fix from weeks to days or hours.
Better audit and insurance evidence. Regulators, cyber insurers and enterprise customers increasingly ask how quickly critical flaws are remediated. A documented, risk-based process answers that with data.
Resilience through layers. Redundant paths and segmentation, such as those built with multi-operator connectivity and SD-WAN, limit what an attacker can reach when one device is compromised before a patch lands.
The outcome is a security program that scales with the threat rather than with headcount.
HIT Communications has operated enterprise networks and communications for more than 30 years across Latin America, the United States and Europe, and we approach vulnerability management as part of one connected environment: network, endpoints, identity, voice and cloud.
Our cybersecurity services combine a 24/7 SOC, SIEM and managed detection and response to detect exploitation early, validate indicators of compromise and guide containment while patches are tested. Our IT managed services keep inventories, patching and backups under control so emergencies do not depend on heroics. And our multi-operator connectivity and SD-WAN designs give you segmented, redundant paths that reduce the blast radius of any single vulnerable device.
Whether you manage a regional network or a multinational estate, we help you turn a flood of CVEs into a short, prioritized list of actions that your team can execute.
Google's data points in one direction: AI is increasing the number of vulnerabilities, raising their severity and shortening the time attackers need to exploit them. The answer is not to patch everything faster, it is to patch the right things first, protect what you cannot patch yet and watch continuously for signs of exploitation.
If you are not sure which of your systems are exposed, how quickly your critical flaws are fixed or whether anyone is monitoring them around the clock, this is the right moment to find out. Contact HIT Communications and schedule a conversation with our team to review your vulnerability and patch management approach.

Find out how we can transform your business. Talk to one of our experts now!
Get in touch