Rapid7’s Q2 2026 threat report found that critical vulnerability disclosures doubled year-over-year, yet only 25 of the 40 exploited flaws needed zero credentials or user interaction to break in. The report’s takeaway: CVSS score matters less than actual exposure, and defenders can’t patch their way out of the gap.
Anders Askåsen, SVP of Strategy and Marketing, Radiant Logic
“25 of the 40 exploited vulnerabilities last quarter needed no credentials at all. So the break-in is cheap. What costs you is what the attacker inherits once inside: the service accounts on that host, the tokens it holds, the systems those entitlements reach. The truth is that exposure matters more than CVSS score. But exposure is not just where a flaw sits in the network. It is what the identities on that machine can do next. And with AI agents now getting credentials faster than most JML processes from your favorite IGA tool were built to handle, very few teams can answer that question.”
Justin Beals, CEO & Founder, Strike Graph
“Rapid7’s numbers confirm what a lot of security leaders have felt but couldn’t prove. Disclosures of high and critical vulnerabilities doubled year over year, but exploited vulnerabilities only grew 8 percent. That gap is the real story. Discovery isn’t the bottleneck anymore, exposure is. For years we scored risk by CVSS and hoped patch windows would catch up. That math never worked, and now AI has widened the gap between disclosure and exploitation faster than a monthly cycle can track. The rise in what Rapid7 calls ‘Holy Grail’ vulnerabilities, the ones that need no credentials and no user interaction, is the part that should worry people most. Those are the flaws that turn a scanner hit into an active breach with nobody doing anything wrong. Teams that keep triaging by severity score alone are going to keep losing this race. The ones who survive will map exposure first, what’s actually reachable, what’s actually exploitable, and treat that as a picture that updates continuously instead of a report that lands once a quarter. A patch cycle built for a slower world isn’t built for this one.”
Expect disclosures and vulnerabilities to increase further as time goes on. That is my take away. That means that patching you way out of this at scale is not an option. Defenders will have to find other ways to deal with this situation. And fast.
Related
This entry was posted on August 18, 2026 at 12:43 pm and is filed under Commentary with tags Rapid7. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
Rapid7’s Q2 2026 threat report is out… And it’s bad
Rapid7’s Q2 2026 threat report found that critical vulnerability disclosures doubled year-over-year, yet only 25 of the 40 exploited flaws needed zero credentials or user interaction to break in. The report’s takeaway: CVSS score matters less than actual exposure, and defenders can’t patch their way out of the gap.
Anders Askåsen, SVP of Strategy and Marketing, Radiant Logic
“25 of the 40 exploited vulnerabilities last quarter needed no credentials at all. So the break-in is cheap. What costs you is what the attacker inherits once inside: the service accounts on that host, the tokens it holds, the systems those entitlements reach. The truth is that exposure matters more than CVSS score. But exposure is not just where a flaw sits in the network. It is what the identities on that machine can do next. And with AI agents now getting credentials faster than most JML processes from your favorite IGA tool were built to handle, very few teams can answer that question.”
Justin Beals, CEO & Founder, Strike Graph
“Rapid7’s numbers confirm what a lot of security leaders have felt but couldn’t prove. Disclosures of high and critical vulnerabilities doubled year over year, but exploited vulnerabilities only grew 8 percent. That gap is the real story. Discovery isn’t the bottleneck anymore, exposure is. For years we scored risk by CVSS and hoped patch windows would catch up. That math never worked, and now AI has widened the gap between disclosure and exploitation faster than a monthly cycle can track. The rise in what Rapid7 calls ‘Holy Grail’ vulnerabilities, the ones that need no credentials and no user interaction, is the part that should worry people most. Those are the flaws that turn a scanner hit into an active breach with nobody doing anything wrong. Teams that keep triaging by severity score alone are going to keep losing this race. The ones who survive will map exposure first, what’s actually reachable, what’s actually exploitable, and treat that as a picture that updates continuously instead of a report that lands once a quarter. A patch cycle built for a slower world isn’t built for this one.”
Expect disclosures and vulnerabilities to increase further as time goes on. That is my take away. That means that patching you way out of this at scale is not an option. Defenders will have to find other ways to deal with this situation. And fast.
Share this:
Like this:
Related
This entry was posted on August 18, 2026 at 12:43 pm and is filed under Commentary with tags Rapid7. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.