The economics of an exploit has officially collapsed

Vishal Santharam,
Product Manager, ManageEngine
dateAug 27, 2026
Collapsed exploit economics as AI lowers the cost of finding and weaponizing vulnerabilities.
Zero-cost AI-assisted exploit development changing attacker economics.

Listen to the article (AI powered narration)

Ever since the announcement of Mythos in April, we've been waiting for the impending apocalypse. While the number of CVEs being detected has continued to increase, I'd argue that the floodgates haven't actually opened yet.

The reason: economics.

cve-releases-chart-editable

Finding a genuinely exploitable vulnerability in a complex, real-world codebase using AI depends on how advanced the reasoning models are. Until recently, the models capable of reasoning through complex code and identifying high-severity vulnerabilities at a meaningful scale were primarily accessible through a small number of frontier AI providers. Accessing those capabilities through metered APIs is expensive, while running comparable models locally required substantial compute infrastructure.

This created a practical barrier to widespread use. The surge you see in the above chart is driven by well-funded labs, nation-states, or well-capitalized attackers with API budget to burn and the infrastructure to support it.

The changing tide

Qwen 3.8, an open-weight model, now operates with the efficiency of frontier models, while running comfortably on a consumer machine.

To test its capability, I asked the model simply to identify vulnerabilities in the current codebase of a widely used open-source agentic coding harness with more than 200k GitHub stars. I left it running unattended overnight, for about 12 hours, on my own Mac. It surfaced three exploitable issues that the maintainers consider outside their scope of fixing.

To check its authenticity, I further asked the model to build an exploit. By lunch, it had handed me a working one.

One of the issues it identified was a deployment exposure in the harness's web API: When authentication is disabled, the API can allow remote command execution. This isn't a product flaw. The exposure results from a user-side misconfiguration, and the maintainers consider it outside their security-fixing scope. Shodan, a search engine for internet-connected devices, shows that over 60 hosts are currently exposed to this misconfiguration. And the cost to build this exploit? Zero.

From an attacker's perspective, the math suddenly looks very different. Since the model is hosted locally, the whole exercise costs literally nothing but time and effort.

What the future looks like

Up until this model was released on August 14th, attackers needed money to be able to run automated exploit hunting. Not anymore. Today, anyone with a laptop and an evening to spare can build a working exploit. That means the economics of this setup favors the attackers more than the defenders and vendors, at least for the next couple of years. You can expect the number of CVEs and exploits to sky rocket.

In the mean time, vendors will work on fixing their own vulnerabilities. Eventually, vendors will reach a state where their old vulnerabilities are fixed completely and the count drops to a manageable number again. So the graph will look something like this.

cve_spike_curve_time_vs_vulnerability_count

What this means for defenders

The time to rebuild your security stack against the resulting surge of exploits should have begun a couple of months back. But it's better to begin late than never. So start now. Your security stack should run in three directions: depth, containment, and machine-speed response.

  1. 01

    Attack surface reduction

    Patching remains foundational, but the priority changes to closing vulnerabilities faster. And autonomous patch management brings speed to the picture. Considering the volume and variety, patches should be complemented by compensating controls such as virtual patching, misconfiguration monitoring and control, dynamic segmentation, and runtime defense. These controls reduce your organization's attack surface and manages exposure without waiting for updates or change windows.

  2. 02

    Blast radius containment

    AI-enabled identification of exploitable paths demands an assume-breach model. Zero Trust architecture becomes foundational; it should operate as a continuous validation system across identity, device, network, and session context, critical to arresting lateral movement under AI-assisted exploitation. The outcome is containment: Even if a vulnerability is exploited, the blast radius is limited by what the compromised system can reach. Movement is restricted, access is bounded, and impact is localized.

  3. 03

    Machine-speed response

    When attacks can unfold in minutes, containment must happen at machine speed. While humans remain on a critical response path, they are not the only one. Autonomous endpoint detection and response (EDR) removes the bottleneck issue, enabling much quicker response.

Together, these layers create a continuous control system: reduce exploitable paths, constrain movement, and break execution in real time.

Here's my deeper take on what needs to be restructured, and how to approach it from scratch.

Trusted by

Unified Endpoint Management and Security Solution