Quantro Security Report Finds AI Agents Can Exploit Vulnerabilities in Minutes for Under $3

Jul 21, 2026
A new report from Quantro Security reveals that autonomous AI agents can develop working exploits for software vulnerabilities in about 11 minutes at a median cost of $2.83.
Quantro Security Report Finds AI Agents Can Exploit Vulnerabilities in Minutes for Under $3

Quantro Security announced in a press release that autonomous AI agents can convert publicly disclosed vulnerabilities into verified working exploits in about 11 minutes for a median compute cost of $2.83. The findings are based on testing 3,029 disclosed CVEs, where AI agents successfully built and verified exploits for 2,183 of them, or 72 percent.

The study used the Quantro Exploit Harness, a system of AI agents that automatically ingests vulnerabilities, develops proofs of concept, and verifies successful execution without human input. Independent verification of the methodology and findings was conducted by Loginsoft.

The report highlights that 73 percent of the AI exploitable vulnerabilities carried an Exploit Prediction Scoring System score below 0.25, indicating that these flaws are often deprioritized by enterprise patching programs. Additionally, 89 percent of these were missing from the Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog.

To help organizations assess and mitigate these threats, Quantro Security is releasing two free tools, AI-XI (AI Exploitability Index) and AI-Recon (AI Native Exposure Scanner), designed to evaluate exploitability and exposure through the perspective of an AI attacker.

We hope you enjoyed this article

Free newsletter

Cybersecurity AI Weekly

Weekly newsletter about AI in Cybersecurity.

Whitepaper

Tensordyne Napier: What If One Rack Could Do the Work of Nine?

Tensordyne

This Tensordyne whitepaper presents Napier, an inference-focused AI processor and rack-scale system based on the company’s TDN Math logarithmic number system. It examines infrastructure requirements for large mixture-of-experts and agentic models, compares major inference architecture approaches, and details the TDN AIP processor, TDN72 pod, TDN Link fabric, and Napier Ultra configuration. The paper reports simulation-based performance, cost, and accuracy-validation results, including Tensordyne’s projected comparison of one Napier rack with a nine-rack Nvidia Rubin plus Groq deployment; the chip is reported as taped out and in fabrication.

Read more
Free, six days a week

Daily AI Brief: the AI news that matters, in your inbox.