VulnCheck's H1 2026 data shows 1.3% of AI assisted findings hit real world exploitation. The bottleneck sits downstream of where the tools run.
AI is shaving weeks off the path from a new vulnerability to a published CVE. The path from a published CVE to a working attack is barely moving, and that gap is what the next round of AI security claims will have to answer for.
VulnCheck's H1 2026 State of Exploitation report is the first dataset in which three of the loudest AI vulnerability-hunting models overlapped. Researchers tracked 1,061 publicly attributed AI-assisted vulnerability discoveries and found that only 14, or 1.3%, were confirmed exploited in the wild. That matches the overall Known Exploited Vulnerabilities (KEV) ratio for the period. "AI is currently better at increasing the volume of vulnerabilities researchers can uncover than at increasing the proportion attackers actually exploit," VulnCheck researcher Patrick Garrity told CyberScoop.
For a non-security reader: an exploit is a working attack against real software, not the same thing as a flagged bug. The KEV catalog, maintained by CISA, is the closest public proxy for which CVEs have been turned into real attacks. The 1.3% number says AI has moved the input side of the security pipeline, not the output side.
The asymmetry is sharpest on Anthropic's flagship. The company's Project Glasswing, launched in April 2026, claims to have surfaced 23,019 vulnerability candidates. Only 126 have been published as CVEs, and just one, CVE-2026-4747, a FreeBSD NFS remote code execution flaw, is explicitly attributed to Glasswing and confirmed exploited. Anthropic has not publicly responded to CSO Online's request for comment on the disclosure gap, and the full accounting of Glasswing findings is not expected until later in 2026.
Two things are happening at once. AI is compressing the upstream, where bugs are found and reported. CISA's median time from CVE publication to KEV listing fell from 120 days in 2025 to 80 days in H1 2026. That is genuine progress, and a real risk to defenders running large fleets. But the KEV-to-CVE ratio dropped from 2.7% in H2 2023 to 1.4% in H1 2026. A faster pipe is moving more water, but a smaller share of it is reaching the destination attackers care about.
The H1 2026 KEV data, broken down by category, also resists the AI-doom narrative. Content management systems accounted for roughly one-third of the 495 KEVs; network edge devices about 14%; operating systems 9%; server software 8%. AI products as a category, including the tools themselves, sit at about 6%, an emerging surface but not the dominant one. The same enterprise software that has driven patching backlogs for a decade is still driving them.
The counterpoint sits in the same Anthropic release that produced Glasswing. The Claude Mythos Preview System Card includes a capability test showing the model's exploit-success rate jumping from near-zero to roughly 72% on a class of targets it struggled with months earlier. SANS Institute and Tanium researcher Melissa Bischoping, commenting on the system card, called that result a sign the defender bottleneck has collapsed, even if the public KEV data has not caught up.
KEV is a lagging indicator: exploitation data only appears after defenders, vendors, and CISA have seen real attacks. A 72% exploit-success rate on a controlled capability test is a forward-looking signal. The H1 window is also partial. Project Glasswing launched in April 2026, Microsoft's MDASH and OpenAI's Daybreak both in May. None of the three ran for the full six months. The 1.3% number is a snapshot of a market that is still warming up, not a steady-state verdict.
For readers who do not run a security team, the takeaway is a framework rather than a verdict. AI in 2026 is a finding accelerant, not yet an exploitation accelerant. The next AI-in-security headline is worth asking three questions: what share of the vendor's findings reached CISA's KEV, what is their median CVE-to-KEV window, and what is their exploit-success rate on an independent capability test rather than a self-reported demo. The bottleneck that decides whether AI shrinks or grows the threat is downstream of where the tools operate. Patch hygiene, disclosure practices, and attacker economics, not the AI model, decide whether any single finding becomes a real incident.