Rapid7 Labs · Research report

Quarterly Threat Landscape Report

The compression era: Q2 2026 has showed that traditional patch cycles are overwhelmed.

Ungated research - no sign-up required

+0%

Disclosures doubled

High- & critical-severity CVEs year-over-year - 8,539 vs 4,268 in Q2 2025

0%

Holy grail flaws

Of exploited vulnerabilities required no auth and no user interaction (25 of 40)

0

U.S. victims

Ransomware leak-site listings in the U.S. - roughly 9× Germany, the next country

0

Underground listings

Exploit & access listings across 20 dark web sources, 23 CVEs actively traded

Introduction

The compression era

Q2 2026 was not just another busy quarter in cyber. It felt more like a stress test of the way we currently manage exposure. Traditional patch cycles are being overwhelmed by the sheer volume of vulnerabilities and attacker speed and precision.

Vulnerabilities are being disclosed at higher volume, proof-of-concept code is appearing faster, exploitability is being tested earlier, and attackers are getting better at turning public information into operational access. For defenders, the issue is not simply that there is more to patch. The real issue is that the time between knowing about a weakness and seeing it used in the wild continues to collapse.

That changes the conversation. This is no longer a world where security teams can rely on traditional patch rhythms, static severity scores, or quarterly prioritization exercises. Attackers have never waited for organizations to get their defenses ready before seeking out exposed systems. But now, they have greater means than ever to get out in front of outdated security programs.

The conversation around Anthropic's AI-assisted vulnerability discovery model, Mythos, and the broader “vulnpocalypse” narrative in cybersecurity circles belongs in this report, but not as science fiction and not as marketing fear. AI does not magically turn every vulnerability candidate into a working exploit nor is finding a bug the same as understanding exploitability.

Real-world exploitation still depends on context: reachable code paths, configuration, authentication state, target architecture and, for example, environmental constraints. For CISOs and security leaders the question is not whether every AI-assisted vulnerability lead becomes a real exploit. Most will not. The question is how much reachable, exploitable exposure an organization is willing to carry when capable adversaries can use automation, tooling, and expertise to move fast through discovery, validation, and targeting.

This is why preemptive security matters. Not as a slogan, but as an operating model. Organizations cannot patch their way out of this by treating every vulnerability as equal. They need to understand what they expose, which assets matter, which weaknesses are actually reachable, which identities can be abused, and where detection must fire before initial access becomes lateral movement.

As you will see in this report, the lessons from Q2 are simple. To defend against an attacker that can compress time, defenders need to compress exposure.

To defend against an attacker that can compress time, defenders need to compress exposure.

- Rapid7 Labs, Q2 2026
Key report takeaways

Five signals that defined Q2 2026

Takeaway 1

High-severity vulnerability disclosures double year-over-year

Disclosures of high- and critical-severity vulnerabilities (CVSS 7–10) doubled year-over-year from 4,268 in Q2 2025 to 8,539 in Q2 2026. New exploited vulnerabilities increased 8% to 40 in Q2. Taken together this points to a widening gap between what’s disclosed and what any team can realistically triage.

Takeaway 2

Rise in zero-interaction “holy grail” vulnerabilities

The proportion of exploited vulnerabilities classified as “holy grail” (network-exploitable, no authentication, no user interaction) increased to 62% (25 of 40), a 9-point year-over-year jump compared to the 53% (24 of 45) observed in Q2 2025.

Takeaway 3

Persistent targeting by nation-state APT clusters

State-aligned advanced persistent threat (APT) groups tied to Iran, North Korea and Russia ran sustained campaigns against finance, government, energy, manufacturing and healthcare.

Takeaway 4

A busy quarter for dark web activity and initial access trading

Dark web monitoring identified 124 exploit and access listings across 20 underground sources. Among the 23 CVEs being traded, most had proof-of-concept (PoC) code, and nearly 40% were exploited in the wild.

Takeaway 5

Ransomware trends and high-risk sectors

Qilin led activity with 263 victims. The United States accounted for 881 of all listed incidents, with business services and healthcare identified as the top targeted sectors.

Q2 2026 leak-site victim counts - top 10 groups

Qilin263
The Gentlemen230
DragonForce141
Akira116
LockBit107
INC94
SafePay49
RALord42
CoinBase Cartel41
SLH39
Geopolitical escalation

Nation-state activity across regions and industries

Q2 2026 featured multiple active nation-state groups targeting a wide variety of regions and industries.

Russian campaigns

APT28 exploited SOHO edge routers for DNS hijacking, potentially allowing for the theft of authentication tokens and passwords.

Iranian campaigns

A sustained industrial control systems/operational technology (ICS/OT) campaign targeting U.S. Programmable Logic Controllers (PLCs) - specifically Rockwell Automation and Allen-Bradley systems.

Top adversary techniques (MITRE ATT&CK)

Application Layer Protocol: Web Protocols · T1071.001 · 90 observedObfuscated Files or Information · T1027 · 86 observedIngress Tool Transfer · T1105 · 70 observed

Sectors actively targeted

FinanceGovernmentEnergyManufacturingTechnologyHealthcareTelecomDigital InfrastructureEducationDefense
The vulnerability intelligence and exploit landscape

Critical exploit tracking

Q2 2026 is all about rapid attack, and rapid response.

Volume and speed

The volume of critical vulnerabilities, up 21% from last quarter, and the rate of publicly available proof-of-concept (PoC) code, are rising, up 12% from last quarter and 76% when compared to 2025 Q2. This indicates a growing number of easily weaponized threats.

Vulnerability disclosures doubled YoY

8,539 new CVSS 7–10 CVEs in Q2 2026 vs 4,268 in Q2 2025 (+100%). Defenders need exposure context prioritization to keep pace, because attackers are already using AI to discover faster.

Attackers have a growing backlog of unauthenticated internet-facing endpoints to weaponize

CWE-306 (Missing Auth) disclosures surged +247% YoY (156 vs 45); SQL Injection (CWE-89) +50% YoY (476 vs 318). Inventory your external attack surface and enforce authentication on every exposed endpoint before the exploitation curve catches up.

The weaponizable pool grew faster than the disclosure pool

Attacker-friendly attributes of newly disclosed CVEs, Q2 2025 → Q2 2026

CWE-306 (Missing Auth)+247% YoY

Q2 202549
Q2 2026156

Holy grail (remote + unauth + zero-click)+114% YoY

Q2 20251,612
Q2 20263,453

Public PoC available+76% YoY

Q2 2025153
Q2 2026270

CWE-89 (SQL Injection)+50% YoY

Q2 2025318
Q2 2026476
Q2 2025Q2 2026
For comparison: confirmed exploited (KEV) fell –21% YoY (45 → 40). See disclosure chart below.

Disclosures doubled. Exploitation didn't.

Q2 2025 → Q2 2026, quarterly - New CVSS 7–10 CVEs disclosed (bars) vs. confirmed exploited on CISA KEV (line)

4,2684,3944,5577,0568,539Q2 2025Q3 2025Q4 2025Q1 2026Q2 2026
Threat actor activity

Active adversary trends and statistics

Q2 2026 is all about rapid attack, and rapid response.

Popular incident techniques. Attackers consistently focus on escalating privileges and moving deeper into the network once an initial foothold is established, with a high prevalence of post-exploitation activity. Credential harvesting, abuse of Remote Management Tools, and exploitation of public-facing software remain popular.

Ransomware activity. US organizations remain the ransomware epicenter - 881 listed victims across Q2 2026, roughly 9× the #2 country, Germany, with 99. But the quarterly top 10 now includes India (35) and Thailand (15). Having two non-western countries in the leaderboard is evidence that affiliate programs are actively expanding beyond English-speaking targets. Security teams in APAC can no longer treat ransomware as mainly a US/EU problem.

Dominant MDR trend themes

Device code phishing and authentication broker abuse

Credential dumping: Local Security Authority Subsystem Service (LSASS) and Mimikatz persistent presence

Ransomware activity: Black Cat, Black Basta, and SentinelOne detections

Labs and IR services - Q2 2026

IR observation

Top ransomware groups Q2 2026

The top 3 ransomware groups of Q2 were Qilin (263 leak posts), The Gentlemen (230), and DragonForce (141).

Top 10 ransomware groups by number of extortion attempts - June 2026

Qilin285
The Gentlemen243
DragonForce144
Akira122
LockBit108
INC Ransom103
SafePay60
RALord59
KryBit56
Coinbase Cartel56

Ransomware incidents by region

Q2 2026 - Share of listed victims by country

United States74.2%
Germany8.3%
United Kingdom6.1%
Canada5.7%
Italy4.6%

Sectors targeted by ransomware

Q2 2026

Business Services23.5%
Healthcare22.0%
Manufacturing21.0%
Technology16.9%
Construction16.6%

IR observation

Fake CAPTCHA and ClickFix social engineering

Fake CAPTCHA and ClickFix social engineering techniques make up 31.8% of observed IR incidents, impacting critical sectors such as healthcare, manufacturing, and communications & media.

IR observation

Social engineering in Microsoft Teams on the rise

Social engineering in Microsoft Teams is becoming increasingly popular, highlighting a shift from phishing emails to trusted internal collaboration channels.

Dark web intelligence

Underground forum signals

Exploit trading on TOR and clearnet forums remains as popular as ever, with traditional vulnerability listings sitting alongside AI-assisted exploit discovery or AI tooling as an attack surface.

0%

Confirmed exploited

(9 of 23) of CVEs traded underground are confirmed exploited on the CISA KEV list

0%

Have public PoCs

(20 of 23) have public proof-of-concept code available for immediate weaponization

0%

Holy grail

(19 of 23) are trivially exploitable - no auth and no user interaction required

Fortinet is referenced in 1 in 16 forum post listings (7 in total) - a reminder of how concentrated attacker attention on edge and remote-access appliances has become.

Recommended actions

00

Inventory and patch internet-facing edge appliances - SSL-VPN, RDP gateways, and web servers.

00

Rotate credentials and enforce phishing-resistant MFA on every remote-access path.

00

Cross-reference CVEs surfacing in disclosure spikes against your asset inventory.

So what does this mean?

The wait-and-see patch cycle is over

The second quarter of 2026 makes one thing painfully clear. The era of the wait and see patch cycle is officially over. Disclosure volume is outrunning any team's capacity to triage it, and the flaws attackers use most need no credentials and no clicks. Adversaries are simply not waiting for organizations to sit around and debate maintenance windows or who owns what. Instead they are actively hunting for the path of least resistance. That could be an unauthenticated edge appliance, a vulnerable identity path, or even a socially engineered trap inside a trusted Microsoft Teams chat.

This is not some hypothetical AI driven vulnpocalypse. It is a highly operationalized landscape where threat actors are aggressively automating their discovery processes. The practical response isn't to chase every new vulnerability - it's to shrink the exposure that is actually reachable. The board will ask how much reachable, exploitable exposure are we carrying? Answering that question with evidence is indicative of a preemptive security program. Attackers have successfully compressed the time it takes to strike, so defenders must now forcefully compress the space in which those attackers can operate.

Chase less. Expose less. Answer the board's exposure question with evidence.

- Rapid7 Labs, Q2 2026
Get started

Outpace attackers. Command your attack surface.

See how a preemptive approach unifies exposure and detection - so you can compress the space attackers have to work in.