Loginsoft Research · in partnership with Quantro Security
AI is Changing Vulnerability Exploitation. See the Research Behind It.
Loginsoft partners with Vulnerability Research Labs (VRL) to measure how AI is transforming the way software vulnerabilities are exploited and what it means for defenders today
.webp)
72%
of analyzed CVEs reached a verified working exploit
$2.83
median cost to build one, end to end
11 min
median time from CVE to verified exploit
308K
tokens to build and validate a single exploit
Why it matters
Your CVSS score cannot see this coming

Traditional vulnerability signals are falling behind the AI era. Research found that 89% of AI-exploitable CVEs weren't in the CISA KEV catalog, 72% had low EPSS scores, nearly 25% were rated below High severity in CVSS, and 450 had no public PoC yet an autonomous system generated exploits for them in 11 minutes at an average cost of $2.83. The takeaway: existing prioritization methods still matter, but they need to be augmented with signals designed for today's AI-driven exploitation landscape.
Two free tools from the VRL research team
Turn the research on your own stack
AI-XI · Exploitability Index
Is this CVE exploitable by AI?
Paste in a CVE. An autonomous agent tries to build and verify a working exploit, then hands back a score from 1 (easy) to 5 (hard), along with the time and cost it took. Never the exploit itself.
Score a CVE
AI-XI · Exploitability Index
Is this CVE exploitable by AI?
Paste in a CVE. An autonomous agent tries to build and verify a working exploit, then hands back a score from 1 (easy) to 5 (hard), along with the time and cost it took. Never the exploit itself.
Score a CVE
Talk to our research team
Want this mapped to your stack?
Share a few details and we will send over a short walkthrough of what VRL's findings mean for the software you actually run, plus a live look at AI-XI and AI-Recon.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Partnership
In Partnership With
Loginsoft contributes vulnerability datasets, threats Intelligence, and independent validation to VRL, while Quantro Security develops the AI-powered Exploit Harness used throughout the research.
