As cited
Copy frozen at (site build).
vulnerabilities
H1 2026 Malware Vulnerability Trends
Insikt Group identified 215 actively exploited common vulnerabilities and exposures (CVEs) in H1 2026, a 34% increase from 161 in H1 2025, with Microsoft accounting for 40 unique vulnerabilities. Threat actors continued to favor abuse of legitimate tools, trusted platforms, and established post-exploitation playbooks across multiple vulnerabilities rather than deploying novel techniques. Artificial intelligence (AI)-enabled malware remained concentrated in lower maturity levels, supporting discrete functions like UI interaction and persistence rather than autonomous operations, while AI-assisted vulnerability research accelerated discovery and exploit development timelines.
Why it matters: Security teams must prioritize vulnerabilities enabling remote code execution or network exploitation without authentication (60 of 215), focus detection on behavioral sequences rather than isolated events, and automate vulnerability enrichment and remediation to close the window before threat actors weaponize disclosed flaws.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
H1 2026 Malware Vulnerability Trends
Insikt Group identified 215 actively exploited common vulnerabilities and exposures (CVEs) in H1 2026, a 34% increase from 161 in H1 2025, with Microsoft accounting for 40 unique vulnerabilities. Threat actors continued to favor abuse of legitimate tools, trusted platforms, and established post-exploitation playbooks across multiple vulnerabilities rather than deploying novel techniques. Artificial intelligence (AI)-enabled malware remained concentrated in lower maturity levels, supporting discrete functions like UI interaction and persistence rather than autonomous operations, while AI-assisted vulnerability research accelerated discovery and exploit development timelines.
Why it matters: Security teams must prioritize vulnerabilities enabling remote code execution or network exploitation without authentication (60 of 215), focus detection on behavioral sequences rather than isolated events, and automate vulnerability enrichment and remediation to close the window before threat actors weaponize disclosed flaws.
- Source published
- First seen by Cybersecurity Tracker