Rapid7 Labs Q2 2026 Report: The End of the Era of Traditional Patch Patterns and the Rise of AI Threats
News | 24.08.2026
Threat research laboratory Rapid7 Labs has released its latest quarterly report, the Quarterly Threat Landscape Report for the second quarter of 2026. The main takeaway of the study is that the traditional vulnerability management model, based on regular update cycles (patch cycles), has officially run its course.
By leveraging automation and artificial intelligence (AI) tools, threat actors are rapidly compressing the time between vulnerability disclosure and practical exploitation. In an environment where the stream of new critical flaws has doubled, trying to "patch everything" becomes an impossible task. The only effective path forward for CISOs and cybersecurity teams is migrating to a Preemptive Security model and shrinking the attack surface that is actually reachable.
As an official distributor of Rapid7 solutions, Softprom provides a detailed breakdown of Q2 2026 key trends along with actionable recommendations to defend your organization.
5 key signals defining the Q2 2026 threat landscape
Data from the Rapid7 Labs report demonstrates a dramatic change in the speed and operating methods of threat groups:
- CVE disclosure volume doubled: In Q2 2026, 8,539 new high- and critical-severity vulnerabilities (CVSS 7.0–10.0) were recorded, compared to 4,268 during the same period last year. Meanwhile, confirmed exploitations grew only slightly (from 42 to 40 in KEV). This highlights that information volume is far outstripping security teams' physical capacity to triage and prioritize.
- Dominance of zero-interaction attacks (Holy Grail): 62% (25 out of 40) of actively exploited vulnerabilities required no user interaction, credential entry, or phishing clicks from the victim. A year prior, this share stood at 53%.
- Explosive surge in authentication flaws: Vulnerabilities related to missing authentication (CWE-306) jumped 247% year-over-year (from 45 to 156). This provides attackers with an open gateway to internet-facing services without needing to compromise passwords.
- Dark web activity and exploit trading: Active trading of 23 CVE specifications was identified across 20 underground forums. Nearly 40% of these are already being exploited in real-world attacks, and 20 out of 23 have publicly available PoC code.
- Evolution of ransomware: Qilin led ransomware activity by victim count (263 victims), followed by The Gentlemen (230) and DragonForce (141). The United States remains the primary target (881 cases), but India and Thailand entered the top 10 for the first time, signaling expanding ransomware activity into the APAC region.
Threat analysis: AI, geopolitics, and social engineering
The Rapid7 study provides an in-depth look at the main attack vectors leveraged by both state-sponsored APT groups and cybercrime syndicates.
The role of artificial intelligence (AI)
The emergence of AI-driven vulnerability discovery tools (such as Anthropic's Mythos model) and discussions surrounding the "vulnpocalypse" have set a new context. While AI does not magically generate a working exploit for every flaw, it dramatically accelerates fuzzing and code analysis stages. Adversaries utilize AI to automate scanning, verify endpoint accessibility, and build targeting scenarios.
Geopolitically motivated APT campaigns
State-aligned threat clusters focused heavily on critical infrastructure, finance, energy, public sector, and telecommunications:
- Russian APT groups (including APT28): Actively targeted SOHO edge devices and SSL-VPN/RDP gateways for DNS hijacking and authentication token theft.
- Iranian groups: Sustained focus on industrial control systems (ICS/OT), specifically targeting Rockwell Automation and Allen-Bradley controllers.
- North Korean actors: Continued targeted campaigns against the financial and technology sectors.
New initial access vectors
According to Rapid7 Incident Response (IR) team data, traditional email phishing is losing ground to more sophisticated techniques:
- Fake CAPTCHA and ClickFix: Social engineering scenarios using fake captchas and error resolution instructions accounted for 31.8% of all investigated incidents.
- Attacks in Microsoft Teams: Adversaries increasingly exploit internal corporate messaging platforms to bypass email filters and deliver malicious code via trusted channels.
Comparing cybersecurity approaches
The Q2 2026 report clearly demonstrates why a traditional reactive approach fails to protect modern businesses against evolving threats.
Traditional approach (Reactive)
- Operating principle: Attempting to remediate all disclosed CVEs based solely on base CVSS scores.
- Response speed: Waiting for scheduled maintenance windows (patch days).
- Outcome: Teams are overwhelmed by routine triage, leaving critical public endpoints exposed to automated AI attacks.
Preemptive approach (Preemptive Security)
- Operating principle: Evaluating actually reachable attack surfaces (Reachable Exposure) while accounting for configuration context and network accessibility.
- Response speed: Immediate neutralization of unauthenticated entry points and isolation of critical assets.
- Outcome: Shrinking the adversary's operational space while giving executive leadership and the board a clear, evidence-backed view of real risk.
Four steps to secure your infrastructure from Rapid7 experts
To mitigate incidents in Q3 2026 and beyond, Rapid7 Labs analysts recommend prioritizing the following actions:
- Perimeter inventory and defense: First and foremost, remediate vulnerabilities on exposed edge appliances (SSL-VPN, RDP gateways, web servers).
- Enforce robust authentication: Implement phishing-resistant multi-factor authentication (MFA) across all remote access points and rotate compromised credentials.
- Prioritize based on reachability: Cross-reference spikes in new CVEs against your actual asset inventory, isolating unauthenticated nodes (CWE-306).
- Dark web and communication channel monitoring: Leverage Threat Intelligence data to track leaks and control internal collaboration channels like Microsoft Teams.
Request a consultation with the Softprom expert team today to evaluate the true security posture of your infrastructure.