Cybersecurity
AI Cheaply Exploits Bugs Risk Models Ignore, Report Says

An AI security startup says its autonomous agents turned disclosed software vulnerabilities into working, verified exploits for a median of $2.83 and roughly 11 minutes each — and that the flaws the agents cracked most easily are the ones many enterprise patching programs are told to skip.
The claim comes from Quantro Security, a New York company founded by veterans of CrowdStrike (CRWD ), Tenable and Qualys that sells an AI-driven vulnerability-management platform. Its report, The Economics of Vulnerability Exploitation with AI, was produced by Vulnerability Research Labs, an in-house unit, with vulnerability data supplied by the firm Loginsoft. Across 3,029 published CVEs, the company reports that its autonomous “Exploit Harness” built a verified proof-of-concept for 2,183 of them — a 72% success rate — at a median compute cost of $2.83 and a median of 11 minutes from ingesting a vulnerability to a working exploit.
The framing is Quantro’s pitch as much as its finding. For most of the past three decades, the practical barrier protecting the long tail of disclosed bugs was labor: writing a reliable exploit took a skilled researcher days or weeks, so only a fraction of flaws were ever weaponized. “When exploitation costs the price of a cup of coffee and takes less than a quarter-hour, ‘unlikely to be exploited’ no longer means safe,” said Mehul Revankar, the company’s chief product officer, in the report’s announcement.
The bugs teams are told to skip
The sharper claim is about which vulnerabilities the agents found easy. According to the report, 73% of the AI-exploitable CVEs carry an Exploit Prediction Scoring System score below 0.25. That model, maintained by the Forum of Incident Response and Security Teams, estimates the chance a flaw will be exploited in the wild within 30 days, and a score that low is where many vulnerability-management programs tell teams to deprioritize patching. Quantro also says 1,933 of the exploitable flaws — 89% — do not appear in the US cybersecurity agency’s Known Exploited Vulnerabilities catalog, the authoritative list of bugs confirmed under active attack.
Both signals were built to answer a human question: is anyone actually bothering to exploit this? Quantro’s argument is that they now miss a different one. “The question defenders must ask is: ‘Can an AI agent exploit this vulnerability automatically?'” said chief executive Sasan Padidar. The company’s proposed fix, unsurprisingly, is to treat AI-exploitability as its own prioritization signal — the thing its platform sells.
What the numbers do and don’t show
Two things temper the topline. This is vendor-originated research measuring the vendor’s own thesis with the vendor’s own tool, a point the report states plainly. And it is not zero-day work: every vulnerability studied was a known, published CVE with a public advisory, so the study measures how cheaply AI can re-exploit what is already documented — not whether it can discover anything new. The dataset also skews toward flaws that could be rebuilt inside a container, leaving out those needing specialized hardware or licensed commercial software.
The autonomy carries an asterisk, too. Quantro says a deterministic verifier — not the model’s own claim — confirmed each exploit fired, with controls to screen out false positives. But of the 998 exploits it had independently checked by hand, 234, roughly one in four, needed a human to correct the AI-generated code before it would verify. The figures cover an April-to-June 2026 window that the company calls a floor rather than a fixed rate.
That caveat cuts both ways. Independent testing has repeatedly shown a gap between what agents manage against neatly described disclosed bugs and what they achieve against real, novel targets — the closer the task moves to genuine discovery, the more success rates fall.
The part that isn’t hypothetical
The direction Quantro is measuring is already visible outside the lab. Google’s Threat Intelligence Group reported in May 2026 that it had identified, for the first time, a zero-day exploit it believes was built with AI — a two-factor-authentication bypass in an open-source administration tool that a criminal group planned to use in a mass-exploitation campaign. The same report described a North Korea-linked group firing thousands of automated prompts to analyze CVEs and validate proof-of-concept exploits, assembling an arsenal the analysts said would be impractical to manage by hand. Vendor reports through the year have tracked the same shift from AI as assistant to active operator.
Alongside the report, Quantro is releasing two free tools: AI-XI, which scores a submitted CVE from 1 to 5 on how readily an agent can weaponize it, and AI-Recon, which maps an organization’s exposed services against the lab’s catalog of verified exploits. Both run on the same harness behind the company’s paid product, so they function as demonstration and sales funnel at once. The prioritization argument doesn’t require buying anything, though; Quantro has published its per-CVE dataset, a more useful response for defenders than taking any single vendor’s 72% on faith.












