8,539 reasons to rethink how vulnerabilities get patched
AI-summarised brief · reviewed before publication
Rapid7’s Q2 2026 Threat Landscape Report documented 8,539 high‑ and critical‑severity vulnerability disclosures, double the count from a year earlier, underscoring a tightening window for remediation. Exploit code appears faster, with a 76 % rise in publicly available proofs of concept compared to Q2 2025, and 62 % of newly exploited flaws are network‑exploitable, requiring no authentication or user interaction. The report warns that reliance on periodic patch cycles and CVSS scores alone leaves organizations chasing “ghosts” while attackers automate kill‑chains and weaponize patches almost instantly. It recommends shifting focus from sheer CVE volume to exposure‑based risk, maintaining accurate inventories of internet‑facing assets such as VPNs and routers, and enforcing authentication on exposed endpoints to curb the expanding attack surface.
💡 Why It Matters
- · Organizations that continue treating patching as a ticket‑closing exercise are effectively funding attackers’ research, while a exposure‑centric approach can cut the path to compromise.