IT Brief Canada - Technology news for CIOs & IT decision-makers
Canada
Rapid7 says exploits are emerging faster than patches

Rapid7 says exploits are emerging faster than patches

Tue, 18th Aug 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

Rapid7 has published its Q2 2026 Threat Landscape Report, which says newly disclosed software flaws are being exploited more quickly.

In the second quarter, 62% of newly exploited vulnerabilities could be attacked remotely without authentication or user interaction, a pattern often described as zero-click exploitation. The report also found a 21% quarter-on-quarter rise in critical vulnerabilities and a 76% year-on-year increase in publicly available proof-of-concept code.

Those figures point to growing strain on patching processes that depend on severity rankings and scheduled remediation cycles. Rapid7 said the gap between disclosure and exploitation has narrowed so much that defenders need to assess whether a weakness is reachable and exploitable in their own environments, rather than relying only on CVSS scores.

High and critical vulnerability disclosures doubled year on year to 8,539, while newly exploited vulnerabilities rose by as much as 40%, underscoring how quickly attackers are moving from disclosure to active use.

One area of concern was the rise in flaws tied to missing authentication. Disclosures in that category climbed 247% year on year, from 45 to 156, broadening the attack surface for internet-facing systems.

Ransomware trends

Beyond software vulnerabilities, the report tracked ransomware activity across multiple regions. The United States accounted for 881 listed ransomware victims in the quarter, compared with 99 in Germany, the next highest country in the dataset.

India and Thailand entered the top 10 countries for listed ransomware victims during the quarter. Rapid7 said the shift suggests affiliate-led ransomware operations are expanding beyond the US and Europe, traditionally their most visible targets.

State activity

The report also examined state-aligned cyber activity linked to Iran, North Korea and Russia. According to Rapid7, campaigns associated with those countries targeted critical infrastructure and enterprise sectors, including by exploiting small office and home office edge routers for DNS hijacking.

Attackers were also actively targeting operational technology and industrial control systems, placing industrial environments and essential services within the same threat picture as conventional enterprise networks.

The findings come as security teams face a rising volume of disclosures and a larger body of exploit material in public forums and code repositories. When proof-of-concept code appears quickly after disclosure, the barrier to entry for criminal groups and other attackers can fall sharply.

Publicly available proof-of-concept code increased 12% from the previous quarter and 76% from a year earlier. In practice, that means defenders are often competing with adversaries who can adapt and reuse code almost immediately after a flaw becomes known.

Rapid7 drew much of its analysis from its managed detection and response operations, vulnerability intelligence platforms and threat research telemetry. The quarterly report also covered geopolitical cyber activity, social engineering tactics, dark web activity and ransomware developments.

Christiaan Beek, Vice President, Rapid7 Labs, said the data shows why security teams need to shift their priorities. "Security teams are chasing ghosts if they think they're 'secure' just by closing tickets based on CVSS scores. We're drowning in a deluge of disclosures, and the gap between a patch existing and an exploit being weaponised has collapsed to near zero," Beek said.

He added that attackers are increasingly automating parts of the intrusion process. "If you're still relying on periodic patch cycles while your adversary is automating their kill chain, you aren't managing risk, you're just subsidising the attackers' R&D. Stop collecting CVEs and start focusing on the exposures that actually matter," Beek said.