NEWNow shipping: ACP · Google UCP · Retail MCP integrations
MnT Future
Market POV

AI Now Finds Vulnerabilities Faster Than Most Stores Patch Them

CEO Udhayaseelan··5 min read
AI Now Finds Vulnerabilities Faster Than Most Stores Patch Them

A US ecommerce team that ships a release on Friday and patches on the next sprint is running on a clock that no longer exists. In its October 1, 2026 research, Google's Threat Intelligence Group reported that monthly CVE disclosures roughly doubled this year, from 5,045 in January to 10,740 in August. The same report found that vulnerabilities likely discovered by AI are more severe than the rest. If your store runs custom code, third-party apps and AI-assisted commits, the question is no longer whether a flaw exists. It is how many days you have once someone else finds it.

The short answer

Answer-engine block: Yes, AI changes ecommerce security timelines. Google's Threat Intelligence Group found that half of the vulnerabilities it attributes to AI discovery lead to remote code execution, versus 26% of those found by other means. With disclosures doubling in 2026, US stores should shorten patch windows, track every dependency, and require senior review of AI-written code before it reaches checkout.

What Google actually reported

The numbers matter, so here they are with their limits. GTIG counted 10,740 CVE disclosures in August 2026 against 5,045 in January. It recorded 141 vulnerabilities exploited in the wild between January and August, compared with 127 in all of 2025. Only 0.23% of disclosed vulnerabilities were exploited, which is worth remembering: most disclosures never become attacks.

The sharper finding is about profile. Among vulnerabilities GTIG judged likely to have been found by AI, 50% led to remote code execution, compared with 26% of those found by other means. Only 39% of the AI-found group rated as low risk, against 69% for the rest.

GTIG also described a case where a flaw in BeyondTrust software, found by an AI security tool, was exploited within four days of disclosure and by five more threat clusters within seven days. That is one documented case, not a universal timeline. But it shows the direction: defenders' AI agents surface high-impact bugs, and attackers read the same disclosures.

Why this lands harder on commerce platforms

A store is not one codebase. It is a storefront, a checkout, a payment integration, a tax engine, an ERP connector, a dozen apps and, increasingly, code that an AI assistant wrote. Each layer has its own disclosure feed and its own owner. When disclosures double, the work of knowing what you run, and who is responsible for each part, doubles with them.

Two US-specific pressures sit on top of that.

PCI DSS v4.0.1. The standard expects critical and high-security patches to be installed within one month of release (requirement 6.3.3), and it expects you to maintain an inventory of the software you run. A store that cannot list its components cannot show it patched them.

AI-written code you did not review. Veracode's Spring 2026 update found that AI-generated code passed security checks about 55% of the time without explicit security guidance, while syntax correctness exceeded 95%. Cross-site scripting passed only 15% of the time and log injection 13%. Code that compiles and looks finished is not code that is safe, and an AI-assisted team ships a lot of it.

Three changes that matter more than a new scanner

Tools help, but the failures we see are mostly about ownership and process. These three changes cost little and close the largest gaps.

1. Keep a living inventory of what runs in checkout

List every package, app, script and service that touches the cart, checkout or customer data, with an owner for each. This is the artifact that makes a one-month patch deadline achievable, and it is the first thing a PCI assessor asks to see.

2. Set a patch clock by severity, and measure it

Define how fast a critical, high and medium fix must ship, then track the actual median. Teams that measure patch time usually discover the real number is longer than the assumed one. If a critical fix takes three weeks, the policy is a hope, not a control.

3. Put a senior engineer between AI-written code and production

AI produces code faster than a junior-heavy team can judge it. The review gate is where risk is caught or missed. Keep that gate with engineers who have seen these failure classes before, particularly around authentication, payment handling and anything that renders user input.

What we do about it

MnT Future builds commerce platforms and AI agents for US D2C and marketplace brands, and our delivery is senior-only commerce platform engineering. That is a staffing decision made for exactly this reason: the person reviewing the code should know what a bad checkout looks like. In our AI Cleanup Lab, we built a deliberately flawed store, exploited it, and rebuilt it with hardened infrastructure. The audit found seven security findings, two of them critical, and all five live exploits we ran were closed after the rebuild. It is our own lab work, not a client engagement, and we describe it that way. See the AI Cleanup Lab results.

We make no claim that any store is unbreakable. Honest security work narrows the window, documents the decisions, and makes the next disclosure a routine fix instead of an incident.

What to do this week

Pull your checkout dependency list. Compare the age of your oldest unpatched critical item against a one-month target. Identify the last AI-assisted change that shipped without a security-focused review. Those three checks take an afternoon and tell you where you stand.

If you want a second pair of eyes, request a free strategy session with our team or ask for a free agent-readiness audit, which also reviews the data and integration layer agents depend on.

Sources: Google Threat Intelligence Group, October 1, 2026 (as reported by Help Net Security, SecurityWeek and Infosecurity Magazine); Veracode, Spring 2026 GenAI Code Security Update (March 24, 2026); PCI DSS v4.0.1 requirement 6.3.3.

Next step

Tell us what you're building. We'll show you how we'd build it.

A free strategy session with a senior consultant: data model, APIs, and a scalability plan. Or a free agent-readiness audit of your store.