Skip to main content

Rapid7 Quarterly Threat Landscape Report Cites Faster Q2 2026 Exploitation

Rapid7, Inc. released its Quarterly Threat Landscape Report covering Q2 2026, reporting changes in how vulnerabilities moved from disclosure to active exploitation. The company tied the shift to faster weaponization and increased vulnerability volumes that affected the usefulness of traditional patch timing based on severity scoring.

In the report, high and critical disclosures totaled 8,539, and newly exploited vulnerabilities increased by up to 40% in Q2 2026. Rapid7 also reported year-over-year doubling for high and critical disclosures, along with a narrowing window between disclosure and active exploit activity.

Rapid7 described several categories of exploitation patterns. It said zero-click vulnerabilities increased, with 62% of newly exploited vulnerabilities categorized as “holy grail” flaws that could be exploited over a network without authentication or user interaction. The report also cited acceleration in weaponization signals, including a 21% quarter-over-quarter increase in the volume of critical vulnerabilities and a rise in publicly available proof-of-concept code by 12% from the previous quarter and 76% year over year. Disclosures involving missing authentication increased 247% year over year, from 45 to 156.

The report addressed ransomware and campaign activity tied to specific nation states. Rapid7 said ransomware remained concentrated but continued expanding geographically, with the United States accounting for 881 listed ransomware victims, about nine times the 99 recorded in Germany; it also said India and Thailand entered the top 10 countries. The report documented state-aligned campaigns from Iran, North Korea, and Russia that targeted critical infrastructure and enterprise sectors, and it cited tactics including exploiting SOHO edge routers for DNS hijacking and actively targeting operational technology and industrial control systems.

“Security teams are chasing ghosts if they think they're 'secure' just by closing tickets based on CVSS scores. We're drowning in a deluge of disclosures, and the gap between a patch existing and an exploit being weaponized has collapsed to near zero,” said Christiaan Beek, Vice President, Rapid7 Labs. “If you're still relying on periodic patch cycles while your adversary is automating their kill chain, you aren't managing risk, you're just subsidizing the attackers' R&D. Stop collecting CVEs and start focusing on the exposures that actually matter.”

Provided by Globe Newswire on behalf of Rapid7. Click to read original content. The original article was written by Decision Insights Editorial.