CVE Tools

Google’s AI security agents found 100+ critical software vulnerabilities in just two days

Help Net SecurityBy Sinisa Markovic

ResearchGoogle

Our summary

Google’s Mandiant unit revealed that its internal Agentic Vulnerability Discovery Harness (AVDH) leverages multiple AI agents to detect security issues in source code efficiently. During a specific incident involving stolen corporate repositories, the system successfully identified more than 100 verified, high-severity vulnerabilities within a 48-hour period. This rapid detection capability led to the assignment of twelve official Common Vulnerabilities and Exposures identifiers, notably CVE-2026-13242 and CVE-2026-55803, with further disclosures currently underway. The findings underscore the growing effectiveness of specialized agentic pipelines in automating complex code reviews compared to traditional scanning methods.

Read at Help Net Security

Help Net Security publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store