Rapid7 Report: Two-Thirds of Q2 2026 Exploits Required No User Input

  • 62% of newly exploited vulnerabilities in Q2 2026 required no user interaction, per Rapid7's Quarterly Threat Landscape Report.
  • High and critical vulnerability disclosures doubled year-over-year to 8,539, with exploited vulnerabilities up 40%.
  • Proof-of-concept exploit code availability rose 76% year-over-year, accelerating weaponization timelines.
  • Ransomware attacks surged in the U.S. (881 victims) compared to Germany (99), with new hotspots in India and Thailand.
  • State-aligned cyber campaigns from Iran, North Korea, and Russia targeted critical infrastructure and operational technology.

Rapid7's findings highlight a fundamental shift in cybersecurity dynamics, where static severity scoring and periodic patching are no longer sufficient. The surge in zero-click vulnerabilities and accelerated weaponization timelines underscores the need for preemptive security approaches. As AI-driven flaw discovery outpaces human response capabilities, the industry faces a critical inflection point in managing exploitable exposures.

Patching Paradigm Shift
How security teams adapt to the collapse of traditional patching cycles amid accelerating exploit timelines.
Exposure Management
Whether evidence-based exposure management becomes the new standard for vulnerability prioritization.
Geopolitical Cyber Risk
The pace at which state-aligned cyber campaigns expand beyond traditional U.S. and European targets.