AI doubles high/critical flaws, overwhelms patch cycles

Rapid7 reports AI-driven tools doubled high and critical vulnerabilities to 8,539 in Q2 2026 and raised newly exploited flaws to 40, overwhelming monthly patch cycles.

Rapid7’s Q2 2026 report, titled “the compression era,” found AI-driven tooling doubled disclosed high and critical vulnerabilities (CVSS 7-10) to 8,539, up from 4,268 in Q2 2025. The firm also recorded 40 newly exploited vulnerabilities in the quarter, an 8% increase from the prior year. Rapid7 said faster proof-of-concept code and earlier exploit testing are narrowing the time defenders have to respond.

Christiaan Beek, Rapid7’s vice president of cyber intelligence, highlighted the gap between discovery and exploitation, noting that exposure determines whether an exploit can be used. He summarized the distinction this way: “Discovery and exploitation are separate issues.” Beek said enterprise environments are growing beyond classic endpoints to include APIs and complex supply-chain links, creating visibility gaps for defenders.

Rapid7 reported an increase in what it calls “Holy Grail” vulnerabilities: flaws that do not require credentials or user interaction to exploit. These unauthenticated, remotely exploitable flaws accounted for 25 of the 40 exploited vulnerabilities in Q2 2026, a nine percentage-point rise year over year. Beek said such flaws allow attackers to act without tricking users and increase the urgency to reduce exposure.

The report links some of the surge to AI-enabled development practices, including so-called vibe coding. Rapid7’s analysis found newly built financial applications with identical weaknesses, which suggests AI models sometimes reuse templates and carry forward known vulnerabilities. Those repeated errors increase the scale of familiar weaknesses that automated scanners can find.

Rapid7 also described persistent nation-state activity and criminal operations. Russia’s activity focused on Ukraine and supporters, Iran targeted the United States and allied countries, China acted mainly against Taiwan, and North Korea pursued financially motivated operations. Rapid7 contrasted motivations and resources across groups, noting nation-state actors often have sustained funding and persistence needs while criminal groups focus on quick gain.

Ransomware remained a primary monetization tactic. In Q2 2026 the United States recorded 881 ransomware victims and Germany recorded 91. The most active groups the firm tracked were Qilin, The Gentlemen, DragonForce, Akira and LockBit. Top targeted sectors by share of incidents included business services (23.5%), healthcare (22.0%), manufacturing (21.0%), technology (16.9%) and construction (16.6%).

Rapid7 recommended shifting triage and remediation away from blanket monthly patch cycles and raw CVSS scores toward prioritizing exposure and reachable assets. Beek warned: “If you still believe we have a monthly patch cycle, forget it.” The report advises organizations to map what parts of their networks are reachable by attackers, reduce unnecessary exposure, and prioritize fixes based on access and potential impact rather than total vulnerability counts.

Articles by this author