High and Critical Vulnerabilities Double Year-on-Year as AI Accelerates Threat Landscape
Rapid7's Q2 2026 report shows vulnerability disclosures surged to 8,539, with 'Holy Grail' flaws now dominating exploits.
The Vulnerability Surge: A System Under Stress
Disclosures of high and critical vulnerabilities (CVSS 7 to 10) have doubled dramatically, jumping from 4,268 in Q2 2025 to 8,539 in Q2 2026. Rapid7’s latest threat report frames this explosion as “the compression era”—a period where traditional patch cycles are being overwhelmed by both vulnerability volume and attacker speed.
AI as the Compressive Force
Rapid7’s VP of cyber intelligence Christiaan Beek identified AI as the compressive force behind the current stress on vulnerability management. He has called for a fundamental shift in defence strategy, stating that monthly patch cycles no longer work. Instead, Beek recommends that defenders prioritise network exposure over CVSS severity scores when triaging new vulnerabilities.
The Rise of ‘Holy Grail’ Exploits
”Holy Grail” vulnerabilities—those requiring no credentials or user interaction—are now dominant in active exploits. These flaws showed a 9-point year-over-year increase and now account for 25 of the 40 exploited vulnerabilities recorded in Q2 2026.
Newly Exploited Vulnerabilities and Ransomware Activity
Newly exploited vulnerabilities increased 8% to 40 in Q2 2026, compared to Q2 2025. On the ransomware front, the most active groups in Q2 2026 were, in order: Qilin, The Gentlemen, DragonForce, Akira, and LockBit.
Source: SecurityWeek