Rapid7, Inc. has released its Quarterly Threat Landscape Report, highlighting that rising vulnerability volumes and faster weaponisation are breaking traditional patching models. The findings reinforce that security teams must move beyond static severity scores and prioritise the exposures that attackers can realistically exploit.
As AI accelerates flaw discovery, the critical challenge for defenders is no longer just finding bugs – it is acting before adversaries do. According to the report, high and critical disclosures doubled year over year to 8,539, with newly exploited vulnerabilities jumping by up to 40%. With the window between disclosure and active exploit shrinking rapidly, relying on static CVSS scores and periodic patching is no longer viable.
“Security teams are chasing ghosts if they think they’re ‘secure’ just by closing tickets based on CVSS scores. We’re drowning in a deluge of disclosures, and the gap between a patch existing and an exploit being weaponised has collapsed to near zero,” said Christiaan Beek, Vice President, Rapid7 Labs. “If you’re still relying on periodic patch cycles while your adversary is automating their kill chain, you aren’t managing risk, you’re just subsidising the attackers’ R&D. Stop collecting CVEs and start focusing on the exposures that actually matter.”
Key findings from the report include:
Zero-click vulnerabilities increased
62% of newly exploited vulnerabilities were ‘holy grail’ flaws that could be exploited over a network without authentication or user interaction.
Weaponisation signals accelerated
The volume of critical vulnerabilities increased 21% quarter over quarter, while publicly available proof-of-concept code rose 12% from the previous quarter and 76% year over year, expanding the pool of vulnerabilities attackers can quickly turn into real-world attacks.
Missing authentication created a growing attack surface
Disclosures involving missing authentication increased 247% year over year, from 45 to 156.
Ransomware remained concentrated but continued expanding geographically
The United States accounted for 881 listed ransomware victims, approximately nine times the 99 recorded in Germany. India and Thailand also entered the quarter’s top ten countries, indicating that ransomware affiliate programmes are extending beyond their historically prominent US and European targets.
What this means for security operations
The second quarter of 2026 makes clear that the traditional wait-and-see patch cycle is no longer enough. With vulnerability disclosures surging and attackers increasingly automating discovery, security teams need to focus less on chasing every new flaw and more on reducing exposure that is actually reachable and exploitable. That shift towards evidence-based exposure management is at the heart of a pre-emptive security approach.






