Security & Threat Intelligence · 18.08.2026, 19:55 UTC
New Report: AI threats are here. Why Q2 2026 signals the end of traditional patch cycles
| Schweregrad | high |
|---|---|
| CVSS | 7.0 |
| Kategorie | Security & Threat Intelligence |
| Quelle | Rapid7 Blog ↗ |
| Veröffentlicht | 18.08.2026 UTC |
Sicherheitsmeldung mit Schweregrad hoch (CVSS 7.0). Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
You can’t patch everything. So what do you fix first? Findings in Q2 2026 have changed traditional answers.The latest Quarterly Threat Landscape Report from Rapid7 Labs shows vulnerability disclosures still surging while attackers use automation and AI-assisted tooling to compress the time between disclosure and exploitation. The gap that patch cycles were built to fill is closing. Speed and volume are overwhelming security teams that have relied on traditional patch cycles and reactive programs. Success going forward can’t be about patching as much as possible - it has to be about understanding what matters most and reducing the exposures attackers can actually reach.Here are the four trends that defined Q2 2026, and what they mean for your security program as you define priorities for Q3 and beyond:The volume of disclosures hit another milestoneThere were 8,539 new high- and critical-severity CVEs (CVSS 7.0–10.0) this quarter- double the number reported in the same quarter last year (4,268). Meanwhile, the number of newly exploited vulnerabilities held roughly steady (40). The takeaway isn’t that exploitation exploded - it’s that disclosure volume is far outstripping what any team can triage.The report breaks down which of those disclosures are actually reachable and how to triage by exploitability instead of severity score alone.Initial access keeps getting easierNearly two-thirds of exploited vulnerabilities this quarter (62%) required no user interaction - no stolen credentials, no phishing victim, no click. Attackers reach and exploit them on their own, and that …