ctipilot.ch

Rapid7 Labs Quarterly Threat Landscape Report, Q2 2026

report · report:rapid7-quarterly-threat-landscape-q2-2026 single-source

Rapid7 Labs quarterly telemetry report for Q2 2026, published 2026-08-18: 8,539 new high- and critical-severity CVEs against 4,268 a year earlier while newly exploited vulnerabilities held roughly steady at 40; 62% of exploited flaws required no user interaction, up from 53%; missing-authentication (CWE-306) disclosures up 247% year on year; Qilin led leak-site activity with 263 victims; ClickFix, fake-CAPTCHA and collaboration-platform social engineering accounted for 31.8% of Rapid7 incident-response engagements. Its argument is that disclosure volume has outpaced any team's triage capacity, so prioritisation must run on reachable exposure (Rapid7 Labs, 2026-08-18).

Coverage timeline
1
first 2026-08-24 → last 2026-08-24
Peak priority
notable
1 notable
Sources cited
1
1 hosts
Sections touched
1
research
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
5
pinned v19.2 · see below

ATT&CK techniques

5 techniques observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1133External Remote Services×1

Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.

Evidence: 2026-08-24/rapid7-q2-2026-disclosure-volume-outpaces-triage · ATT&CK page ↗

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-08-24/rapid7-q2-2026-disclosure-volume-outpaces-triage · ATT&CK page ↗

T1566.003Phishing: Spearphishing via Service×1

Adversaries may send spearphishing messages via third-party services in an attempt to gain access to victim systems. Spearphishing via service is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of third party services rather than directly via enterprise email channels.

Evidence: 2026-08-24/rapid7-q2-2026-disclosure-volume-outpaces-triage · ATT&CK page ↗

Execution TA0002

T1204.004User Execution: Malicious Copy and Paste×1

An adversary may rely upon a user copying and pasting code in order to gain execution. Users may be subjected to social engineering to get them to copy and paste code directly into a Command and Scripting Interpreter. One such strategy is "ClickFix," in which adversaries present users with seemingly helpful solutions—such as prompts to fix errors or complete CAPTCHAs—that instead instruct the user to copy and paste malicious code.

Evidence: 2026-08-24/rapid7-q2-2026-disclosure-volume-outpaces-triage · ATT&CK page ↗

Persistence TA0003

T1133External Remote Services×1

Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.

Evidence: 2026-08-24/rapid7-q2-2026-disclosure-volume-outpaces-triage · ATT&CK page ↗

Impact TA0040

T1486Data Encrypted for Impact×1

Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.

Evidence: 2026-08-24/rapid7-q2-2026-disclosure-volume-outpaces-triage · ATT&CK page ↗

Story timeline

  1. 2026-08-24Rapid7's Q2 2026 quarterly report: high- and critical-severity disclosures doubled year on year to 8,539 while the number newly exploited held flat at 40 — and 62% of what was exploited needed no user interaction at all
    researchRapid7 Q2 2026: disclosure volume doubled, exploitation did not — and missing-authentication disclosures rose 247%

Where this entity is cited

  • research1

Source distribution

  • rapid7.com1 (100%)

explore in graph

Entries about Rapid7 Labs Quarterly Threat Landscape Report, Q2 2026 (1)

2026-08-24 · view entry permalink →

NOTABLEexploitedNATOB2

Rapid7's Q2 2026 quarterly report: high- and critical-severity disclosures doubled year on year to 8,539 while the number newly exploited held flat at 40 — and 62% of what was exploited needed no user interaction at all

Rapid7 Labs published its Quarterly Threat Landscape Report for Q2 2026 on 2026-08-18 (Rapid7 Labs, 2026-08-18). One pair of numbers carries the argument: "There were 8,539 new high- and critical-severity CVEs (CVSS 7.0–10.0) this quarter- double the number reported in the same quarter last year (4,268)," while the count of vulnerabilities newly observed under exploitation "held roughly steady (40)" — a comparison the report makes without stating the period it is against, in a paragraph whose preceding sentence is year-on-year. Rapid7 is explicit that the finding is not an exploitation surge but a triage-capacity one — disclosure volume is far outstripping what any team can work through.

Three further measurements give that a defensive shape. First, the exploited set has moved further out of the user's hands: "Nearly two-thirds of exploited vulnerabilities this quarter (62%) required no user interaction - no stolen credentials, no phishing victim, no click," up nine points from 53% in Q2 2025 — meaning awareness training and phishing-resistant authentication, whatever else they buy, are addressing a shrinking share of what actually gets exploited. Second, disclosures of missing-authentication flaws (CWE-306) rose 247% year on year, which Rapid7 frames as a fast-expanding pool of internet-facing systems requiring no login at all; that is a category where an asset-exposure question answers the risk question directly, without needing a severity score. Third, on the intrusion side, Qilin led ransomware activity with 263 listed victims, the United States remained the most-targeted country, and business services and healthcare were among the hardest-hit sectors — while ClickFix and fake-CAPTCHA campaigns together with social engineering through trusted collaboration platforms such as Microsoft Teams accounted for 31.8% of the incidents Rapid7's incident-response team worked. Rapid7 also records continued Iranian, North Korean and Russian state-nexus activity against government, finance, healthcare, manufacturing, energy and telecommunications, with Russian campaigns focused on edge infrastructure and Iranian activity including sustained ICS and OT targeting.

Rapid7's own conclusion is a prioritisation argument rather than a patching one: as disclosures keep growing, the organisations that stay ahead will not be the ones patching fastest but the ones that know what they expose, which assets matter most, where an attacker can realistically get in, and how to reduce reachable exposure before it becomes an incident.

There were 8,539 new high- and critical-severity CVEs (CVSS 7.0–10.0) this quarter- double the number reported in the same quarter last year (4,268).

Nearly two-thirds of exploited vulnerabilities this quarter (62%) required no user interaction - no stolen credentials, no phishing victim, no click.

Rapid7 Labs 2026-08-18
annual-report24 Aug 09:14Zsingle-sourceOpen finding ↗
Sources: Rapid7 Labs