Vulnerabilities & Exploits

GTIG Sees AI Pushing Flaws Into Faster Exploitation

Google Threat Intelligence Group said on September 30 that vulnerabilities it judged likely AI-discovered were twice as likely to lead to remote code execution, and that exploited flaws rose faster in 2026 than zero-days. It tied that shift to faster disclosure-to-exploit cycles, with one AI-found bug, CVE-2026-1731 in BeyondTrust Privileged Remote Access and Remote Support, weaponized within days.

The pattern is plain: once a patch or proof of concept is public, AI tools can help turn it into working exploit code quickly, so the danger window moves into the days after disclosure, not just the zero-day phase. GTIG also said edge and security appliances remain a major target class, and that many of the exploited flaws it tracked there were high or critical risk.

For teams that depend on rapid remediation of internet-facing appliances and remote-support platforms, the practical exposure is shrinking time, not just more bugs. The reporting does not show that AI creates every exploit, but it does show that disclosed fixes are becoming usable faster, especially where a public-facing device can be reached directly.

3 sources · 4h ago

CVE-2026-1731

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: beyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. Known ransomware campaign use. EPSS 91% (100th percentile).

CISA federal remediation date Feb 16 · date passed

Timeline

Sources

Vendor digest: Citrix

Part of the PlainSec briefing for 2026-09-30

Every edition of this story: GTIG Sees AI Pushing Flaws Into Faster Exploitation

More from today