Rapid7 Report: Vulnerability Disclosures Double, Overwhelming Patching Efforts
Rapid7's Q2 2026 Threat Landscape Report reveals a twofold increase in high- and critical-severity vulnerability disclosures, straining security teams and highlighting the need for exposure-based prioritization over traditional CVSS scoring.

The cybersecurity landscape is facing an unprecedented surge in disclosed vulnerabilities, with Rapid7's Q2 2026 Threat Landscape Report identifying 8,539 high- and critical-severity flaws. This figure represents a staggering twofold increase compared to the same period last year, placing immense pressure on security teams to effectively prioritize and expedite their patching processes. The report underscores a critical challenge: the growing difficulty in managing an ever-expanding vulnerability inventory amidst a rapidly shrinking window between disclosure and weaponization.
"Security teams are chasing ghosts if they think they’re ‘secure’ just by closing tickets based on CVSS scores. We’re drowning in a deluge of disclosures, and the gap between a patch existing and an exploit being weaponized has collapsed to near zero," stated Christiaan Beek, Vice President, Rapid7 Labs. He further emphasized the futility of relying on periodic patch cycles when adversaries are automating their attack chains, suggesting that organizations are inadvertently subsidizing attackers' research and development efforts by merely collecting CVEs instead of focusing on actual exposures.
Adding to the complexity, the number of newly disclosed vulnerabilities with publicly available proof-of-concept (PoC) code saw a significant 76% increase year-over-year. This proliferation of readily available exploit code makes it easier for malicious actors to test and weaponize newly discovered weaknesses, further compressing the already tight response timelines for defenders.
A concerning trend highlighted in the report is the increasing prevalence of network-exploitable vulnerabilities that require neither authentication nor user interaction. During the quarter, 62% of newly exploited vulnerabilities fell into this category. These flaws offer attackers a direct path into vulnerable systems without the need to first compromise credentials or trick users into executing malicious files, making internet-facing devices such as VPNs, remote access gateways, and web servers particularly attractive targets.
Beyond technical vulnerabilities, the report also notes evolving social engineering tactics. Fake CAPTCHA and ClickFix techniques accounted for over 31.8% of observed incident response cases, often tricking users into running malicious commands by presenting them as solutions to browser issues. Furthermore, social engineering efforts are increasingly leveraging platforms like Microsoft Teams, blending malicious communications with familiar workplace interactions.
Ransomware attacks continue to be a significant concern, with the United States reporting the highest number of victims at 881 during the quarter. Business services and healthcare remain top targeted sectors. State-aligned threat groups from Iran, North Korea, and Russia are noted for their sustained campaigns across various critical infrastructure and industry sectors, employing tactics like DNS hijacking via compromised routers and targeting industrial control systems.
The underground market for vulnerability information and exploit access remains active, with exploit and access listings observed across 20 different sources. Many of these traded vulnerabilities already had public PoC code or were listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, reinforcing the urgency for organizations to address these known threats.
Rapid7's findings strongly advocate for a strategic shift in vulnerability management. Instead of solely relying on severity scores like CVSS, organizations must prioritize based on actual exposure and reachability. Maintaining an accurate inventory of externally accessible systems, identifying which vulnerabilities are reachable, and enforcing robust access controls are crucial steps. This exposure-based approach allows security teams to focus their limited resources on the threats that pose the most immediate and significant risk, rather than being overwhelmed by the sheer volume of disclosed vulnerabilities.