CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

New Report: AI threats are here. Why Q2 2026 signals the end of traditional patch cycles

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4601

As cited

Copy frozen at (site build).

vulnerabilities

New Report: AI threats are here. Why Q2 2026 signals the end of traditional patch cycles

Rapid7 Labs' Q2 2026 Quarterly Threat Landscape Report shows vulnerability disclosures doubling year over year to 8,539 critical and high-severity CVEs, while exploitation attempts remain flat, widening the gap between patching capacity and disclosure volume. Attackers are increasingly leveraging automation and AI tooling to compress disclosure-to-exploitation timelines, with 62% of exploited vulnerabilities requiring no user interaction and missing-authentication vulnerabilities surging 247% year over year. The report identifies persistent nation-state activity from Iranian, North Korean, and Russian groups targeting critical sectors, and notes that ransomware remains concentrated with Qilin leading victim counts while social engineering through trusted platforms expands.

Why it matters: Security teams relying on traditional patch cycles face an untenable triage burden; practitioners must shift focus from patching volume to identifying and reducing reachable exposures that attackers can actually exploit, prioritizing internet-facing systems with missing authentication and evaluating which assets matter most to their organization.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

New Report: AI threats are here. Why Q2 2026 signals the end of traditional patch cycles

Rapid7 Labs' Q2 2026 Quarterly Threat Landscape Report identifies four key trends reshaping security priorities: vulnerability disclosures doubled year-over-year to 8,539 critical and high-severity CVEs while actual exploitation remained flat at 40 cases, creating a severe volume-to-impact mismatch. Initial access vulnerabilities requiring no user interaction grew from 53% to 62% of exploited flaws, with missing-authentication disclosures surging 247% year-over-year. Nation-state actors from Iran, North Korea, and Russia continued targeting government, finance, healthcare, and critical infrastructure, while Qilin ransomware led the leaderboard with 263 victims and the United States as the primary target. The report recommends shifting from speed-based patching to exposure-reduction strategies focused on reachable vulnerabilities.

Why it matters: Security teams deciding Q3 2026 priorities must recognize that traditional patch cycles cannot keep pace with disclosure volume; instead, focus on identifying and remediating vulnerabilities that are actually reachable and exploitable before attackers compress the disclosure-to-exploitation window further.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

New Report: AI threats are here. Why Q2 2026 signals the end of traditional patch cycles

Rapid7 Labs' Q2 2026 Quarterly Threat Landscape Report identifies four key trends reshaping security priorities: vulnerability disclosures doubled year-over-year to 8,539 critical and high-severity CVEs while actual exploitation remained flat at 40 cases, creating a severe volume-to-impact mismatch. Initial access vulnerabilities requiring no user interaction grew from 53% to 62% of exploited flaws, with missing-authentication disclosures surging 247% year-over-year. Nation-state actors from Iran, North Korea, and Russia continued targeting government, finance, healthcare, and critical infrastructure, while Qilin ransomware led the leaderboard with 263 victims and the United States as the primary target. The report recommends shifting from speed-based patching to exposure-reduction strategies focused on reachable vulnerabilities.

Why it matters: Security teams deciding Q3 2026 priorities must recognize that traditional patch cycles cannot keep pace with disclosure volume; instead, focus on identifying and remediating vulnerabilities that are actually reachable and exploitable before attackers compress the disclosure-to-exploitation window further.

VendorsMicrosoft
Actorsqilin
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary