The Most Vulnerable AI Products Are Among the Most Frequently Exposed on the Internet
According to a preview of the annual internet exposure report released by internet monitoring company Censys, as of early 2026, North America hosts approximately 38% of the world's internet-exposed industrial control systems (ICS), ranking first. Meanwhile, the number of publicly accessible AI services has grown rapidly, increasing from 183,000 IP addresses in October 2025 to 294,000 by early 2026. Notably, AI products with the most severe vulnerabilities (such as Langflow and LiteLLM) saw the largest increases in internet-exposed instances, with Langflow growing by 169% over nine months, accumulating 18 vulnerabilities, of which 14 are high-severity and 4 have been exploited; LiteLLM's exposed instances nearly doubled, and it has a pre-authentication SQL injection vulnerability that is being actively exploited. The total number of ICS devices increased from 129,000 in 2024 to 138,000 by early 2026, with Asia's share rising and Europe's declining.

At a Glance
- As of early 2026, North America hosts the largest share of internet-exposed industrial control systems (ICS) globally, accounting for about 38% of all such devices. The figure comes from a preview of the annual internet exposure report by internet monitoring firm Censys.
- Meanwhile, the number of publicly accessible AI tools is growing rapidly: Censys detected more than 294,000 IP addresses associated with AI services in early 2026, up from 183,000 in October 2025.
- The data highlights the vast attack surface facing hackers intent on disrupting critical infrastructure or subverting the AI tools that enterprises increasingly rely on.
Deep Dive
AI services are not only increasingly present on the public internet, butthe most vulnerable products are also the most frequently exposed. Censys detected a 169% increase in instances of Langflow, an AI agent-building tool, over the past nine months, and the software has accumulated 18 vulnerabilities since 2024 (14 rated high severity, 4 already exploited in the wild).
"Multiple unauthenticated remote code execution (RCE) vulnerabilities make any internet-exposed instance a serious risk," Censys said.
Internet-exposed instances of LiteLLM, another common AI tool, nearly doubled during Censys's observation window, while hackers continue to exploit apre-authentication SQL injection vulnerability(CVE-2026-42208). LiteLLM acts as a unified hub for connecting commercial large language models; once its data is compromised, attackers can obtain API keys that customers use for all such services.
The ICS landscape reflected in Censys data is equally concerning.
The number of internet-exposed ICS devices has grown from 129,000 in 2024 to 138,000 in early 2026, heightening the danger to the global community—because the equipment underpinning energy grids, hospitals, and water systems remains within easy reach of hackers.
Although the vast majority of these devices are located in North America, Asia's share of systems has grown over the past two years, rising from 23% in 2024 to 27% in early 2026. Europe's share declined slightly, from 36% to 31%.
Other aspects of the ICS landscape remained stable. "Over the past two and a half years, about 70% of hosts running ICS devices and services worldwide have consistently been on consumer and mobile networks," Censys said. Commercial networks and cloud platforms accounted for a notably smaller share; Censys did not provide exact percentages, but charts indicate roughly 25% and 5%, respectively.