Recorded Future’s threat intelligence research group Insikt Group has released a report on malware and vulnerability trends for the first half of 2026, identifying 215 actively exploited vulnerabilities—up 34% from H1 2025.
According to the report, exploitation was reported or detected an average of 564 days after disclosure, indicating ongoing attacker interest in older vulnerabilities alongside the targeting of newly disclosed flaws.
The report says Microsoft remained the vendor most frequently associated with exploited vulnerabilities, accounting for 40 unique CVEs in H1 2026, up from 28 in H1 2025—a 43% year-on-year increase. Red Hat ranked second with 15 CVEs, followed by Cisco with 13, Vercel with 11, and Fortinet with nine. At a product-family level, Windows and Windows Server accounted for the largest concentration, followed by Red Hat Enterprise Linux, Vercel Next.js, Cisco Catalyst SD-WAN Manager, and Apple iOS and iPadOS.
Of the 215 unique exploited CVEs, 66 had public proof-of-concept exploits. The report notes that public exploit availability can reduce the time and expertise required to test or operationalise a vulnerability, but does not necessarily indicate an exploit was independently tested or reliably weaponised.
Insikt Group said activity in H1 2026 showed attackers continuing to abuse legitimate tools, trusted platforms, and routine workflows already present in enterprise and consumer environments. The report says threat actors used exposed software, developer tools, remote access utilities, payment workflows, and third-party services to gain access, steal credentials, move laterally, and monetise intrusions while blending into expected activity.
The report argues that this reliance on familiar tools and workflows increases the risk that malicious activity will progress through approved services before defenders recognise it, and points to areas including exposure management, identity and credential governance, behavioural detection, developer-environment security, backup resilience, mobile fraud monitoring, and third-party oversight.
On the use of AI, Insikt Group said “AI-enabled cyberattacks became more visible in H1 2026, but remained mostly additive to established intrusion tradecraft.” It added that AI-assisted research increased the volume of vulnerability reports, which could compress remediation timelines by accelerating exploit-path analysis and lowering exploit-development costs for skilled operators.
“Alert volume will continue to be a challenge for security teams,” said Dan Elliott, field CISO, APJ for Recorded Future. “The solution will be in knowing which vulnerabilities threat actors are actually using. Being able to identify and triage them at AI speed, is what will separate teams that get ahead of exploitation from the ones reading about it after the fact.”
On malware trends, the report said 43 of the 215 actively exploited vulnerabilities (20%) were linked with known post-exploitation malware and tooling. It said stealware was the most common category, followed by offensive security tools, backdoors, remote access trojans, ransomware, broader hacking tools, loaders, mobile malware, exploit kits and web shells, and botnets and malware packers.
The report also highlights supply chain compromises, describing threat actors abusing trusted access paths, software distribution channels, and intermediary platforms to reach downstream victims at scale. It said available evidence from H1 2026 showed repeated compromise of systems aggregating sensitive customer, patient, financial, or operational data, including medical sales platforms, digital health services, insurance environments, financial institutions, and blockchain governance controls. It added that abuse of package managers and developer tooling was prominent, including compromised maintainer accounts, package lifecycle scripts, and developer platforms used to steal credentials and propagate malicious packages.
Insikt Group said Magecart activity in H1 2026 showed greater emphasis on abusing trusted third-party services for skimming payload delivery and data exfiltration, with public reporting highlighting the use of legitimate services including Google Tag Manager and Stripe as part of skimming infrastructure.
You can read the full report here.

