Rapid7 Says Vulnerability Disclosures Doubled in Q2
Rapid7's Q2 2026 threat report says disclosures of high- and critical-severity vulnerabilities doubled to 8,539 from 4,268 a year earlier, while newly exploited vulnerabilities rose 8% to 40. The company argues that monthly patch cycles and severity-only queues cannot absorb that gap, so defenders should prioritize reachable exposure and high-impact assets.
Rapid7's Q2 2026 threat report says disclosures of high- and critical-severity vulnerabilities doubled year over year, rising to 8,539 from 4,268. Newly exploited vulnerabilities increased 8% to 40 over the same comparison, leaving a much larger pool of reported flaws than any team can investigate and patch uniformly.
SecurityWeek reported the findings on August 18 after interviewing Christiaan Beek, Rapid7's vice president of cyber intelligence. Both sources frame the problem as a compression of defensive time, but the figures also show an important distinction: faster discovery does not mean every disclosed flaw becomes a working real-world exploit.
Exposure changes the priority order
Rapid7 says 25 of the 40 exploited vulnerabilities in Q2 required no authentication and no user interaction, up from 24 of 45 a year earlier. The report calls these network-exploitable, zero-interaction flaws especially attractive targets because an attacker can act without first obtaining credentials or persuading a user to click.
At the same time, the report says confirmed exploited vulnerabilities fell 21% year over year even as the broader pool of high-severity disclosures doubled. That is why Rapid7 argues against ranking remediation solely by CVSS score. Reachability, asset importance, authentication state, known exploitation, and available compensating controls determine which flaws create immediate exposure.
What changes for vulnerability programs
The report recommends inventorying internet-facing edge appliances, enforcing phishing-resistant multifactor authentication on remote-access paths, and cross-referencing disclosure spikes against the organization's actual asset inventory. These steps do not replace patching. They narrow the queue so limited remediation capacity reaches the systems most likely to provide an attacker a usable path.
For security and engineering teams, the operational test is whether the vulnerability program can answer three questions quickly: Is the affected component present, is the vulnerable path reachable, and what business impact follows if the host is compromised? A monthly severity-ranked backlog cannot answer those questions at the speed described in the report. Continuous asset context, exploit intelligence, and temporary controls must work alongside permanent fixes.
Rapid7's measurements come from its own research and telemetry, and SecurityWeek's interview adds context rather than an independent replication of the dataset. The report therefore supports a change in prioritization practice, not a claim that AI has made every newly reported vulnerability immediately exploitable.
Key Points
- 1Rapid7 counted 8,539 high- and critical-severity vulnerability disclosures in Q2 2026, double the 4,268 reported for Q2 2025.
- 2Newly exploited vulnerabilities rose 8% to 40, and 25 of those 40 required neither authentication nor user interaction.
- 3The report recommends prioritizing reachable exposure and business impact instead of treating CVSS severity or a monthly patch queue as sufficient.
Scoring Rationale
The report supplies current cross-industry vulnerability and exploitation measurements with direct implications for remediation strategy. The findings are operationally important but come primarily from one vendor's research and telemetry.
Sources
Primary source and supporting public references used for this report.
Practice interview problems based on real data
1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.
Try 250 free problems

