Published · 5d agoSecurity3 min read
Rapid7 counted 8,539 high-severity CVEs and 40 exploited ones. Patch coverage is now a vanity metric
Disclosures doubled year over year while actually-exploited vulnerabilities rose 8%. The arithmetic retires patch-everything SLAs and leaves exploitability triage as the defensible option.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- Rapid7 Labs reported 8,539 new high- and critical-severity CVEs (CVSS 7.0-10.0) in Q2 2026, double the 4,268 reported in the same quarter of 2025.
- New exploited vulnerabilities increased 8% to 40 in Q2 2026; Rapid7's own blog describes the count as holding roughly steady at 40.
- Rapid7's report, titled 'the compression era', states that traditional patch cycles are being overwhelmed by the sheer volume of vulnerabilities and attacker speed and precision, and that Q2 2026 felt like a stress test of the way exposure is currently managed.
- An exploited-vulnerability count of 40 representing an 8% year-over-year increase implies a Q2 2025 figure of about 37.
- Between Q2 2025 and Q2 2026 there were 4,271 additional high- and critical-severity disclosures alongside about three additional exploited vulnerabilities, a marginal ratio of roughly 1,424 disclosures per additional exploited flaw.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Rapid7 Labs counted 8,539 new high- and critical-severity CVEs (CVSS 7.0-10.0) in Q2 2026, double the 4,268 it counted in the same quarter of 2025, while newly exploited vulnerabilities rose 8% to 40 [1][2]. That divergence is not a story about AI being scary; it is an arithmetic problem that quietly retires patch coverage as a program metric.
Work the numbers. If 40 is an 8% increase, the prior-year figure was roughly 37 exploited vulnerabilities [4]. So the industry generated 4,271 additional high-severity disclosures to accompany three additional exploited flaws, a marginal ratio of about 1,424 to one [5]. The share of high- and critical-severity disclosures that saw exploitation in-quarter fell from roughly 0.87% to 0.47% [6]. Put another way, each exploited vulnerability now sits behind about 213 disclosures rather than 115 [7].
The operational consequence lands on anyone whose remediation SLA is expressed as a percentage of high and critical findings closed inside a window. Holding that percentage flat across this period required doubling throughput in twelve months, because the denominator doubled [8]. Teams that hit their number did so by getting a smaller and smaller fraction of relevance for the same effort. Rapid7's own report language calls it "a widening gap between what's disclosed and what any team can realistically triage" [9]. Christiaan Beek, Rapid7's VP of cyber intelligence, told SecurityWeek that "discovery and exploitation are separate issues" and that an attacker cannot use an exploit if the target sits behind multiple firewalls and other defensive mechanisms [10].
If severity score is a bad filter, the report offers better ones. Rapid7 says 62% of exploited vulnerabilities in Q2 2026 required no user interaction at all, up nine points from 53% a year earlier [11]. In the SecurityWeek account, Rapid7 categorises flaws needing neither credentials nor user interaction as "Holy Grail" bugs and puts them at 25 of the 40 exploited [12]. Reinforcing that, disclosures of missing-authentication flaws (CWE-306) rose 247% year over year [13]. Reachability, authentication requirement and internet exposure are countable properties of an asset. They are a triage function. A CVSS band is not.
The exploitation that did happen stayed concentrated. Qilin led ransomware activity with 263 listed victims, followed in order by The Gentlemen, DragonForce, Akira and LockBit [14][15]. The United States recorded 881 victims against Germany's 91, roughly 9.7 times as many [16][17]. Business services (23.5%) and healthcare (22.0%) were the hardest-hit sectors [18]. Rapid7's incident response team also attributes 31.8% of the incidents it worked to ClickFix, fake CAPTCHA campaigns and social engineering through trusted collaboration platforms including Microsoft Teams [19]. That last figure deserves attention from anyone whose entire exposure budget goes to CVE remediation. Rapid7 separately reports persistent Iranian, North Korean and Russian APT clusters, with Russian campaigns against edge infrastructure and Iranian activity sustained against ICS and OT [20].
Beek also points at supply for the disclosure curve: he cites research on so-called vibe-coded financial applications that all contained the same vulnerabilities, suggesting AI is reproducing old mistakes from old templates [21]. If that holds, the denominator keeps growing regardless of anyone's staffing plan.
The report's conclusion is that the winners will be the organisations that know what they expose and reduce reachable exposure, which Rapid7 calls preemptive security as an operating model [22]. It is also a vendor asking readers to open the full report before pressure-testing their Q3 prioritisation [23], so treat the framing accordingly and check the arithmetic, which stands on its own.
What to watch: whether the exploited count stays near 40 next quarter while disclosures keep climbing, because a flat numerator is what makes exploitability triage defensible. Watch the CWE-306 trend, since missing authentication converts disclosure directly into reachable exposure. And watch whether boards accept a metric other than percentage coverage, because that is the actual blocker.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Rapid7 Labs reported 8,539 new high- and critical-severity CVEs (CVSS 7.0-10.0) in Q2 2026, double the 4,268 reported in the same quarter of 2025.
- [2]
New exploited vulnerabilities increased 8% to 40 in Q2 2026; Rapid7's own blog describes the count as holding roughly steady at 40.
- [3]
Rapid7's report, titled 'the compression era', states that traditional patch cycles are being overwhelmed by the sheer volume of vulnerabilities and attacker speed and precision, and that Q2 2026 felt like a stress test of the way exposure is currently managed.
ReportedView cited source - [9]
Rapid7's report describes 'a widening gap between what's disclosed and what any team can realistically triage'.
- [10]
Christiaan Beek, Rapid7's VP of cyber intelligence, said 'Discovery and exploitation are separate issues' and that AI can do both, but an attacker cannot use the exploit if the target is sitting behind multiple firewalls and other defensive mechanisms.
- [11]
Nearly two-thirds of exploited vulnerabilities in Q2 2026 (62%) required no user interaction, up nine points from 53% in Q2 2025.
Sources & coverage · 3 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- blog.rapid7.comRapid7 Labs5d agoNew Report: AI threats are here. Why Q2 2026 signals the end of traditional patch cycles
- securityweek.comKevin Townsend5d agoAI-Driven Vulnerability Surge Breaks the Traditional Patching Model
- helpnetsecurity.comAnamarija Pogorelec



