AI and Automation Accelerate Vulnerability Exploitation, Outpacing Traditional Patching
Rapid7's Q2 2026 report indicates a surge in vulnerability disclosures, with AI and automation enabling attackers to exploit flaws faster than organizations can patch them.

Rapid7 Labs' latest Quarterly Threat Landscape Report for Q2 2026 paints a stark picture of the evolving cybersecurity threat environment, highlighting a dramatic increase in vulnerability disclosures that are being exploited at unprecedented speeds due to the proliferation of AI and automation tools. The report reveals that the sheer volume of new Common Vulnerabilities and Exposures (CVEs) has doubled year-over-year, overwhelming traditional security approaches that rely on reactive patching cycles.
In Q2 2026, security teams were confronted with 8,539 new high- and critical-severity CVEs, a significant leap from the 4,268 reported in the same quarter of the previous year. While the number of newly exploited vulnerabilities remained relatively stable, the vast increase in disclosures means that the gap between a vulnerability being announced and it being weaponized is shrinking rapidly. This trend signals a fundamental challenge to existing security models, forcing a re-evaluation of how organizations prioritize and manage their attack surface.
A critical finding from the report is the increasing ease with which attackers can gain initial access. A substantial 62% of exploited vulnerabilities in Q2 2026 required no user interaction, such as stolen credentials or phishing clicks. This represents a nine-point increase from Q2 2025, underscoring a growing reliance on exploiting unauthenticated flaws in internet-facing systems. The report notes a 247% year-over-year surge in disclosures related to missing authentication vulnerabilities (CWE-306), creating a rapidly expanding pool of accessible targets.
Beyond the technical exploitation trends, the report also details persistent nation-state activity. Advanced persistent threat (APT) groups from Iran, North Korea, and Russia continued their campaigns, targeting critical sectors including government, finance, healthcare, manufacturing, energy, and telecommunications. Specific focus areas included edge infrastructure, industrial control systems (ICS), and operational technology (OT), indicating a strategic interest in disrupting essential services and infrastructure.
Ransomware activity, while concentrated, also showed evolution. The Qilin ransomware family led in victim count, with the United States remaining the most targeted country, particularly impacting business services and healthcare. Incident response teams observed an increase in social engineering tactics, including the use of fake CAPTCHA campaigns and manipulation through trusted collaboration platforms like Microsoft Teams, which accounted for a significant portion of incidents.
The core message from Rapid7's analysis is that the future of cybersecurity resilience lies not in the ability to patch everything, but in the strategic reduction of an organization's attack surface. The sheer volume and speed of exploitation necessitate a shift from a reactive patching strategy to a proactive one focused on understanding what assets are most exposed, where attackers are most likely to gain entry, and how to effectively reduce that reachable exposure before an incident occurs.
This proactive approach, termed "preemptive security," is presented not merely as a slogan but as a necessary operating model for modern security programs. The report provides detailed insights into where reachable exposure is concentrated, offers actionable recommendations, and breaks down risks by sector, all aimed at helping organizations prioritize their defenses effectively in the face of escalating threats.