The Vulnerability Surge: A System Under Stress

Disclosures of high and critical vulnerabilities (CVSS 7 to 10) have doubled dramatically, jumping from 4,268 in Q2 2025 to 8,539 in Q2 2026. Rapid7’s latest threat report frames this explosion as “the compression era”—a period where traditional patch cycles are being overwhelmed by both vulnerability volume and attacker speed.

AI as the Compressive Force

Rapid7’s VP of cyber intelligence Christiaan Beek identified AI as the compressive force behind the current stress on vulnerability management. He has called for a fundamental shift in defence strategy, stating that monthly patch cycles no longer work. Instead, Beek recommends that defenders prioritise network exposure over CVSS severity scores when triaging new vulnerabilities.

The Rise of ‘Holy Grail’ Exploits

”Holy Grail” vulnerabilities—those requiring no credentials or user interaction—are now dominant in active exploits. These flaws showed a 9-point year-over-year increase and now account for 25 of the 40 exploited vulnerabilities recorded in Q2 2026.

Newly Exploited Vulnerabilities and Ransomware Activity

Newly exploited vulnerabilities increased 8% to 40 in Q2 2026, compared to Q2 2025. On the ransomware front, the most active groups in Q2 2026 were, in order: Qilin, The Gentlemen, DragonForce, Akira, and LockBit.


Source: SecurityWeek