Yaamlabs

Vulnerabilities

Google: CVEs doubled in 2026 and AI finds riskier flaws

Google's threat team says monthly CVEs doubled this year and half of AI-found flaws allow code execution. How to change patch timelines and what to inventory.

Google Threat Intelligence Group (GTIG) published a study on September 30 of vulnerability disclosure and exploitation from January 2025 to August 2026. Monthly CVE disclosures went from 5,045 in January 2026 to 10,477 in July and 10,740 in August. In the first eight months of 2026, GTIG saw 141 distinct vulnerabilities exploited in the wild, more than the 127 it counted for all of 2025.

The part that matters for patch planning is the type of flaw. Of the vulnerabilities GTIG judged likely to have been found by AI agents, 50% lead to remote code execution (RCE), against 26% of all other CVEs. If you run internet-facing remote access tools, AI gateways or agent builders such as Langflow, Flowise or LiteLLM, the report describes the kind of software attackers are reaching for this year.

What the numbers say

Exploitation grew as well. GTIG counts an average of 18 exploited vulnerabilities a month in 2026, up from 10.5 in 2025. Of the 141 exploited this year, 62% were zero-days, meaning attackers used them before a fix existed. Zero-days averaged 11 a month in 2026 against 8 in 2025, then jumped to 22 in August.

GTIG also rates each flaw on its own risk scale, separate from CVSS. Disclosures it rated high risk went from 131 in January to 350 in August, a 167% rise. Exploited high-risk flaws reached 75 by the end of August, against 28 for the whole of 2025.

The raw count overstates the threat, and GTIG says so. Only 0.23% of 2026 disclosures, roughly 1 in 431, were seen exploited. Automated CVE assignment in open-source projects inflates the total: entries mentioning the Linux kernel alone produced about 5,000 CVEs this year, with no zero-day among them seen exploited. A team that tries to patch every CVE in order will spend its time on that noise.

Where AI-found flaws and AI software fit

GTIG identifies AI-discovered flaws from vendor and AI lab disclosures and from advisories that credit an autonomous agent, such as Hacktron AI, with the find. Among those, 58% rate as medium risk and 39% as low, against 28% medium and 69% low for everything else. The agents are turning up a higher share of bugs that end with an attacker running commands.

The software being attacked has changed too. GTIG tracked 2,076 AI-related disclosures since January 2025, more than 1,500 of them in 2026. About half hit orchestration and agent frameworks such as Flowise and Langflow. These tools are built to execute code: a visual workflow has nodes that run Python or shell commands so the agent can act on its environment. If the endpoint that accepts a workflow, a file or a tool configuration does not check who is calling or what it is being told to run, an HTTP request becomes code execution on the host. Inference and serving software such as vLLM, Ollama and LiteLLM accounted for another 212 disclosures.

Only a handful of the 2,076 AI-related flaws have been confirmed exploited. Two of them, in LiteLLM and Langflow, show how little an attacker needs once one of these tools faces the internet.

What attackers are doing

BeyondTrust, CVE-2026-1731, CVSS 9.9. Hacktron AI's agent found an unauthenticated OS command injection in BeyondTrust Remote Support and Privileged Remote Access. A crafted request runs operating system commands as the site user, with no login. BeyondTrust disclosed it on February 6, 2026. According to GTIG, one threat cluster was exploiting it within four days of disclosure and five more within a week. They used it for privilege escalation and data theft, and dropped the SNOWLIGHT and SPARKRAT malware and cryptominers.

LiteLLM, CVE-2026-42271, CVSS 8.7. LiteLLM is a proxy that puts many model providers behind one OpenAI-compatible API and stores their API keys. Versions 1.74.2 to 1.83.6 have two Model Context Protocol (MCP) test endpoints, POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list, that accept a server definition with command, args and env fields and start that command as a subprocess. Any holder of a proxy key can run commands on the host. Chained with CVE-2026-48710, a Host header check bypass in the Starlette web framework, no key is needed. CISA added it to its Known Exploited Vulnerabilities (KEV) catalog in June 2026.

Langflow, CVE-2026-5027, CVSS 8.8. The POST /api/v2/files upload handler takes the filename from the Content-Disposition header and writes it to disk unchanged, so ../ sequences place files anywhere the process can write. Langflow's default auto-login hands out a session token to any client, which removes the login step. Attackers have used it to write cron jobs and SSH keys.

What to do

  1. Patch the three named flaws now. BeyondTrust: self-hosted Remote Support 25.3.2 or later, Privileged Remote Access 25.1 or later, or apply patch BT26-02-RS or BT26-02-PRA. Remote Support older than 21.3 and PRA older than 22.1 must be upgraded before the patch will apply. SaaS instances were patched on February 2. LiteLLM: 1.83.7 or later, with Starlette 1.0.1. Langflow: 1.9.0 or later.
  2. If you cannot patch Langflow or LiteLLM today, take them off the internet. Put them behind a VPN or an IP allowlist, set LANGFLOW_AUTO_LOGIN=false for Langflow, and block the /mcp-rest/test/ paths for LiteLLM at the reverse proxy. For BeyondTrust, restrict the appliance interface to known admin addresses.
  3. Check for compromise. On Langflow hosts, look for unexpected files in /etc/cron.d/, new lines in ~/.ssh/authorized_keys and new .py files in the Python package directories. On LiteLLM, search proxy access logs for requests to /mcp-rest/test/ and look for child processes of the LiteLLM service. Anything exposed and unpatched since the flaw was public should be treated as compromised until checked.
  4. Rotate every provider API key a LiteLLM proxy held if the host was exposed. For Langflow, rotate the database credentials and API keys stored in its flows and global variables.
  5. Find the AI tools you did not know about. Teams often start these frameworks on a laptop or a cloud VM without telling IT. Scan your address ranges and cloud accounts for the default ports: Langflow 7860, Flowise 3000, Ollama 11434 and LiteLLM 4000. On container hosts, docker ps --format '{{.Image}}' | grep -Ei 'langflow|flowise|litellm|ollama|vllm' finds running images, and pip list 2>/dev/null | grep -Ei 'langflow|litellm' covers Python installs.
  6. Shorten the clock for internet-facing code execution. The second graphic below is the patch clock we suggest. BeyondTrust shows why the clock starts when the vendor ships the fix: six groups were exploiting it within a week of disclosure.

Changing how you rank patches

GTIG's advice is to move from patching everything in order to triage driven by threat intelligence. In practice that means ranking on three questions: can it be reached from the internet, does it give code execution, and is anyone exploiting it. Edge and security appliances made up 14% of exploited flaws this year, and they usually answer yes to the first two.

AI frameworks belong in the top tier for a specific reason. They hold API keys, sit next to internal data and run code by design, so a single missing check on an upload or test endpoint gives the attacker the whole host. GTIG also recommends running sandboxed agent workloads and, for software vendors, AI-assisted code review before release, so the bugs agents are good at finding get fixed before attackers find them.

Finding the AI services nobody registered is where our attack surface management work starts, and our AI-native systems team reviews how agent frameworks are deployed and locked down. Open the chat and Yaali, our AI agent, will pass your question to an engineer.


Sources: Google Threat Intelligence Group report, SecurityWeek, SiliconANGLE, The Record, Arctic Wolf on CVE-2026-1731, Canadian Centre for Cyber Security AL26-003, CSA on LiteLLM CVE-2026-42271, CSA on Langflow CVE-2026-5027, Orca on CVE-2026-5027.

Back to the blog, or read this post on the full site.