AI Is Driving a 51% Surge in New Vulnerabilities, Forescout Finds

I have been warning about AI-powered attacks for years. Most of the time, those warnings felt premature. Not this week. Forescout Technologies released its 2026H1 Threat Review on July 21, 2026, and the report makes uncomfortable reading for anyone responsible for security.

The headline numbers are big. Published vulnerabilities jumped 51% year-over-year to 37,137. Ransomware attack claims rose 25% to 4,544 incidents, averaging 25 attacks per day. Active ransomware groups hit 103, up 16%. But the underlying trend is what should concentrate the mind.

AI is compressing the attack timeline

Daniel dos Santos, VP of Research at Forescout, put it plainly: “AI is dramatically increasing the speed and scale of cyberattacks.” The report found that rapid advances in AI and frontier models are helping threat actors discover and exploit vulnerabilities faster than security teams can realistically remediate them.

This is not theoretical. Forescout’s Vedere Labs team tracked more than 37,000 newly published vulnerabilities in just the first half of 2026. That is over 200 new CVEs every single day. In a world where AI can scan codebases, generate exploits, and move laterally across networks in minutes, the old quarterly patch cycle is a relic.

The attack surface is also expanding beyond traditional IT. Forescout noted that threat actors are increasingly targeting operational technology, IoT devices, medical equipment, programmable logic controllers, and human-machine interfaces. These systems often receive less security oversight than servers and workstations, and attackers know exactly where the blind spots are.

What this means in practice

The practical implications are clear. Your team is being asked to defend against a flood of vulnerabilities that grows by roughly 10% each month. At the same time, attackers using AI can identify the most critical flaws, chain them together, and launch campaigns in hours instead of weeks.

Here is what should happen immediately:

  • Map your entire attack surface. Include IoT, OT, and IoMT devices. You cannot protect systems you do not know exist, and these are exactly the systems attackers are targeting first.
  • Prioritise exposure management. Knowing a CVE exists is useless if you cannot see which assets are actually exposed. Focus on internet-facing and critical systems first.
  • Segment your networks. Contain east-west movement so a single compromise does not become a full breach. Zero trust is not just a buzzword here; it is a survival strategy.
  • Accelerate patching cycles. The window between disclosure and exploitation is shrinking. Move critical updates from monthly to weekly, or faster where possible.
  • Invest in visibility before AI-powered defence. AI-assisted detection is valuable, but only if you can see the traffic and assets you are trying to protect. Visibility without segmentation is better surveillance of a sinking ship.

Forescout also highlighted that 46% of additions to CISA’s Known Exploited Vulnerabilities catalog were CVEs published before 2026. Old vulnerabilities are still being weaponised, which means unpatched systems from previous years remain live targets. Adding new CVEs on top of an existing backlog creates a compounding risk that many teams simply cannot clear.

This is not a call to panic. Panic does not close ports or apply patches. It is a call to treat AI-driven threat acceleration as a structural shift, not a temporary spike. The organisations that will weather this period best are the ones that combine strong asset visibility with disciplined network segmentation and faster remediation cycles.

The barrier to entry for sophisticated attacks is dropping while the volume of vulnerabilities is rising. Security teams do not need to work harder. They need to work smarter, faster, and with better visibility into what actually lives on their networks.

Related Reading

The views expressed on this site are my own and do not represent those of any current or former employer. Articles are based on publicly available information and are provided for general educational purposes.

Subscribe

Related articles

Google’s Gemini AI Autonomously Hacked Three Companies. Here’s What Happened.

Google has confirmed its Gemini AI autonomously hacked three real companies during a security test. The model guessed passwords, searched for leaked credentials, and accessed protected systems before stopping itself.

440 AI Agents Broke Into 395 Organisations in 26 Seconds. Nobody Stopped Them.

A swarm of 440 AI agents exploited two PaperCut flaws and compromised 395 organisations across 48 countries. The agents reached domain admin in 6 hours and ignored explicit instructions to stay out of 28 countries.

For $3,000 and a Few Days, Researchers Used Claude to Hack OpenAI

Security researchers used Anthropic's Claude AI to hack OpenAI's internal systems for less than $3,000 in tokens. What the HEIF Heist tells us about the new economics of cyber attacks.

The AI Hacking Crisis Is Already Here. Six New Incidents Prove It

OpenAI disclosed six new incidents where its models concealed mistakes, sought unauthorised credentials and uploaded files to the public internet. Cybersecurity experts say the real risk is powerful models meeting poor security controls.

Inside OpenAI’s Log of Misbehaving Models: Rewriting Jailbreaks and Covering Up Errors

OpenAI published six new reports of its models rewriting jailbreak instructions and concealing errors during training, alongside a faster public disclosure framework.
Philip Hall
Philip Hall
Philip Hall is a Sydney-based Cyber AI and Automation leader with more than 30 years of technology experience and a career in cyber security dating back to 2008. His work spans cyber architecture, cloud security, threat intelligence, assurance, incident support, AI-enabled defence and the security of autonomous agents.