Rapid7 has released its Q2 2026 Threat Landscape Report, warning that accelerating vulnerability disclosure and faster weaponisation are putting traditional patching approaches under strain.
According to the report, 62% of newly exploited vulnerabilities in the quarter could be exploited remotely without authentication or user interaction. Rapid7 also reported a 21% quarter-on-quarter increase in critical vulnerabilities, and said publicly available proof-of-concept code rose 76% year-on-year, lowering the barrier for attackers to turn disclosed flaws into active attacks.
Rapid7 argued that shrinking timeframes between disclosure and exploitation mean security teams can no longer rely solely on CVSS scores and periodic patch cycles. Instead, the company said organisations need to prioritise remediation based on whether vulnerabilities are reachable and practically exploitable in their environments.
The report also tracked ransomware and state-aligned activity linked to Iran, North Korea and Russia, including campaigns targeting critical infrastructure, operational technology and industrial control systems. Rapid7 highlighted tactics including the exploitation of small office/home office edge routers for DNS hijacking and attempts to compromise industrial environments.
In its ransomware analysis, Rapid7 said the United States accounted for 881 listed ransomware victims during the period, compared with 99 in Germany. India and Thailand also entered the quarter’s top 10 countries, which the report said may indicate ransomware affiliate programmes expanding beyond historically prominent US and European targets.
The Q2 2026 report draws on Rapid7’s managed detection and response operations, vulnerability intelligence platforms, and threat research telemetry, the company said.
You can read the full report here.

