Rapid7 released its Quarterly Threat Landscape Report on August 18, 2026. High and critical vulnerability disclosures doubled year-over-year to 8,539.
Traditional patching models are becoming obsolete as the window between disclosure and exploitation collapses. Zero-click vulnerabilities accounted for 62% of newly exploited flaws. These flaws allow network exploitation without any user interaction.
Publicly available proof-of-concept code increased 76% year-over-year. Security teams must shift from static severity scores to prioritizing vulnerabilities that are actively exploitable.