Google Threat Intelligence Group’s latest research points to a reality defenders are already feeling: vulnerability management is no longer just a monthly patching discipline. AI-assisted discovery, faster disclosure cycles, and quicker n-day weaponization are turning patch decisions into a threat-intelligence problem.

The headline is not simply “more CVEs.” GTIG reported that monthly vulnerability disclosures roughly doubled in 2026, while observed exploitation also rose meaningfully. Just as important, the exploitation pressure remains concentrated around the systems attackers already love: edge appliances, security gateways, collaboration platforms, directory-adjacent services, and externally reachable management planes.

Original source: Google Threat Intelligence Group — Vulnerability Discovery and Exploitation Trends in the AI Era.

What changed

GTIG’s analysis separates raw disclosure volume from real-world attacker behavior. That distinction matters. A flood of low-context CVEs can make every dashboard look urgent, but only a small slice of disclosed vulnerabilities is observed in active exploitation. The operational risk comes from knowing which slice overlaps with exposed assets, attacker interest, exploit availability, and business impact.

The report also highlights a more uncomfortable shift: AI can help defenders find higher-impact issues, but once those issues are disclosed, attackers can use automation to compare versions, interpret patches, synthesize proof-of-concept logic, and compress the time between advisory and exploitation. In other words, the patch window for important n-days is shrinking.

Why SMBs and government contractors should care

Small and midsize organizations rarely have the staffing to treat every new CVE as a full emergency. Government contractors also have a second problem: they need to show evidence that risk decisions are controlled, repeatable, and tied to the systems that actually support contracts, CUI handling, remote access, and business operations.

The old model—patch everything by severity score alone—breaks down when disclosure volume spikes. CVSS is useful, but it does not know whether your vulnerable product is internet-facing, whether it protects identity infrastructure, whether it stores regulated data, or whether active exploitation has been observed against comparable environments.

The better model is exposure-aware triage: first identify what attackers can reach, then layer in credible threat intelligence, then patch or isolate based on operational risk. This is especially important for VPNs, firewalls, mail systems, remote management tools, file-transfer systems, identity providers, ticketing systems, and collaboration platforms.

Defensive takeaways

  • Separate “new” from “exploitable in your environment.” Build a view of internet-facing products, privileged internal services, and contractor-critical systems before trying to process every advisory.
  • Prioritize known exploitation and edge exposure. If a vulnerability affects a public management interface, remote-access service, security appliance, or collaboration hub, move it above routine internal patching.
  • Track n-day weaponization, not just zero-days. Attackers do not need a zero-day if an advisory gives them enough information to reverse-engineer a working exploit before defenders patch.
  • Preserve evidence before rushing changes on suspected exploited systems. For edge devices and mail/collaboration servers, patching without log preservation can erase the best chance to confirm compromise.
  • Document exceptions like an auditor will read them. If a patch cannot be applied immediately, record exposure, compensating controls, owner, deadline, and validation steps.

Bulwark Black assessment

AI does not make every vulnerability equally urgent. It makes weak prioritization more expensive. The organizations that do well in this environment will not be the ones that blindly chase every CVE alert. They will be the ones that know their exposed assets, enrich patch decisions with threat intelligence, and can prove why the top risks were handled first.

For government contractors, that discipline is more than good security hygiene. It supports incident readiness, supplier assurance, CMMC-style control evidence, and defensible risk management when the next high-profile appliance or collaboration-platform vulnerability lands.