Skip to main content

Cybersecurity statistics / Exploits

50% of AI package vulnerabilities have a publicly available exploit, a 250-fold increase over 2024.

PublisherOrca Security
Report2026 State of AI Security Report
Published9 July 2026
TopicsExploits, AI Security, AI Package Vulnerabilities

Published by Orca Security in 2026 State of AI Security Report, 9 July 2026. The figure is taken from the report as published; the full methodology is in the source.

View the original report

Related statistics

More than 1,700 successful exploits occured across production coding, productivity, and first-party AI agents during adversarial testing.
Straiker, 18/07/2026
62.0% of critical vulnerabilities with known exploits had a working exploit available before scanner detection signatures shipped.
Cogent Security, 31/05/2026
Exploits remained the most common initial infection vector for the sixth consecutive year, accounting for 32% of intrusions.
Mandiant, 27/05/2026
Exploits were observed being weaponised in minutes.
Hive Pro, 10/07/2025
Exploits spiked 657% in browsers.
Action1, 15/05/2025
Exploits spiked 433% in Microsoft Office applications. Web browsers and Office applications have emerged as prime targets. Chrome specifically led all products in known attacks.
Action1, 15/05/2025

Get the newsletter

Weekly cybersecurity statistics by email.