Security3 distinct publishers3 min readPublished Updated
Disclosures doubled year over year while actually-exploited vulnerabilities rose 8%. The arithmetic retires patch-everything SLAs and leaves exploitability triage as the defensible option.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Rapid7 Labs counted 8,539 new high- and critical-severity CVEs (CVSS 7.0-10.0) in Q2 2026, double the 4,268 it counted in the same quarter of 2025, while newly exploited vulnerabilities rose 8% to 40 [1][2]. That divergence is not a story about AI being scary; it is an arithmetic problem that quietly retires patch coverage as a program metric.
Work the numbers. If 40 is an 8% increase, the prior-year figure was roughly 37 exploited vulnerabilities [4]. So the industry generated 4,271 additional high-severity disclosures to accompany three additional exploited flaws, a marginal ratio of about 1,424 to one [5]. The share of high- and critical-severity disclosures that saw exploitation in-quarter fell from roughly 0.87% to 0.47% [6]. Put another way, each exploited vulnerability now sits behind about 213 disclosures rather than 115 [7].
The operational consequence lands on anyone whose remediation SLA is expressed as a percentage of high and critical findings closed inside a window. Holding that percentage flat across this period required doubling throughput in twelve months, because the denominator doubled [8]. Teams that hit their number did so by getting a smaller and smaller fraction of relevance for the same effort. Rapid7's own report language calls it "a widening gap between what's disclosed and what any team can realistically triage" [9]. Christiaan Beek, Rapid7's VP of cyber intelligence, told SecurityWeek that "discovery and exploitation are separate issues" and that an attacker cannot use an exploit if the target sits behind multiple firewalls and other defensive mechanisms [10].
If severity score is a bad filter, the report offers better ones. Rapid7 says 62% of exploited vulnerabilities in Q2 2026 required no user interaction at all, up nine points from 53% a year earlier [11]. In the SecurityWeek account, Rapid7 categorises flaws needing neither credentials nor user interaction as "Holy Grail" bugs and puts them at 25 of the 40 exploited [12]. Reinforcing that, disclosures of missing-authentication flaws (CWE-306) rose 247% year over year [13]. Reachability, authentication requirement and internet exposure are countable properties of an asset. They are a triage function. A CVSS band is not.
The exploitation that did happen stayed concentrated. Qilin led ransomware activity with 263 listed victims, followed in order by The Gentlemen, DragonForce, Akira and LockBit [14][15]. The United States recorded 881 victims against Germany's 91, roughly 9.7 times as many [16][17]. Business services (23.5%) and healthcare (22.0%) were the hardest-hit sectors [18]. Rapid7's incident response team also attributes 31.8% of the incidents it worked to ClickFix, fake CAPTCHA campaigns and social engineering through trusted collaboration platforms including Microsoft Teams [19]. That last figure deserves attention from anyone whose entire exposure budget goes to CVE remediation. Rapid7 separately reports persistent Iranian, North Korean and Russian APT clusters, with Russian campaigns against edge infrastructure and Iranian activity sustained against ICS and OT [20].
Beek also points at supply for the disclosure curve: he cites research on so-called vibe-coded financial applications that all contained the same vulnerabilities, suggesting AI is reproducing old mistakes from old templates [21]. If that holds, the denominator keeps growing regardless of anyone's staffing plan.
The report's conclusion is that the winners will be the organisations that know what they expose and reduce reachable exposure, which Rapid7 calls preemptive security as an operating model [22]. It is also a vendor asking readers to open the full report before pressure-testing their Q3 prioritisation [23], so treat the framing accordingly and check the arithmetic, which stands on its own.
What to watch: whether the exploited count stays near 40 next quarter while disclosures keep climbing, because a flat numerator is what makes exploitability triage defensible. Watch the CWE-306 trend, since missing authentication converts disclosure directly into reachable exposure. And watch whether boards accept a metric other than percentage coverage, because that is the actual blocker.
Ranked by verification strength, evidence, and original report placement.
Rapid7 Labs reported 8,539 new high- and critical-severity CVEs (CVSS 7.0-10.0) in Q2 2026, double the 4,268 reported in the same quarter of 2025.
New exploited vulnerabilities increased 8% to 40 in Q2 2026; Rapid7's own blog describes the count as holding roughly steady at 40.
Rapid7's report, titled 'the compression era', states that traditional patch cycles are being overwhelmed by the sheer volume of vulnerabilities and attacker speed and precision, and that Q2 2026 felt like a stress test of the way exposure is currently managed.
Rapid7's report describes 'a widening gap between what's disclosed and what any team can realistically triage'.
Nearly two-thirds of exploited vulnerabilities in Q2 2026 (62%) required no user interaction, up nine points from 53% in Q2 2025.
Rapid7 uses the term 'Holy Grail' for vulnerabilities requiring neither credentials nor user interaction, and reports these accounted for 25 of the 40 exploited vulnerabilities in Q2 2026, a nine-point year-over-year increase.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Consistent numbers, single-vendor provenance
The core figures are specific, internally consistent and reproduced identically by an independent outlet (8,539 vs 4,268; 40 exploited; 25 of 40; 881 vs 91; 31.8%). But every number traces to one vendor's telemetry, the supplied sources contain no methodology for how 'newly exploited' or 'reachable exposure' are counted, and the full report itself is not in evidence. The AI-causation layer is interview assertion plus unnamed vibe-coding research, which is markedly weaker than the counting claims.
No defender-practice data in sources
The cluster's thesis is that patch-coverage SLAs should give way to exploitability and exposure triage, but neither supplied source reports any organisation actually changing prioritisation practice, any tooling deployment, or any measured remediation-throughput outcome. What is measured is threat-side telemetry (exploited counts, ransomware victims, IR technique shares), which documents the problem rather than uptake of the prescribed model, so adoption cannot be scored without inference.
Framing outruns the flat exploitation count
Headlines on both sides announce the end of traditional patching and an AI-driven vulnerability surge, yet the reported data shows exploitation essentially flat (40, +8%) while disclosures doubled - a pattern the vendor's own analyst attributes partly to defences holding, not to a new exploitation wave. AI is asserted as the compressive force without measurement separating AI-assisted from conventional exploitation, and the prescribed remedy coincides with the publishing vendor's product category. The underlying counting claims are solid, so the gap is one of framing and causal attribution rather than fabricated numbers.
Vendor telemetry with gated call to action
The primary source is a vulnerability-management vendor's marketing post whose every section defers detail to a downloadable report and which concludes that the answer is the vendor's own 'preemptive security' operating model. The independent write-up is editorially separate but is built on the same vendor dataset plus a vendor executive interview, with no external corroboration in the supplied material, so commercial incentive shapes both the data and the prescription.
Counts dependable, causation and adoption unverified
Two publishers agree on the numbers and the arithmetic consequence for coverage SLAs is robust regardless of methodology, which supports moderate confidence in the story's central quantitative point. Confidence is held down by single-vendor provenance, undisclosed counting methodology, an unmeasured AI-causation layer, and a complete absence of defender-adoption evidence.
security
Ransomware hit government entities once a day through the first half of 20261 distinct publisher
security
CRPx0 climbed to 46 claimed victims in July on countdowns that fired in near unison1 distinct publisher
security
Ransomware's price point is $10m to $1bn in revenue, and it is not moving1 distinct publisher
security
A North Korean IT worker got hired by a federal agency. Vetting is a security control now.1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 18, 2026
1 article · August 19, 2026
1 article · August 18, 2026