---
schema: 1
kind: annual-report
title: "Rapid7 Q1 2026 Threat Landscape Report: vulnerability exploitation now top initial-access vector at 38 %; KEV median time to listing collapses to 5 days"
headline: "Rapid7 Q1 2026 Threat Landscape Report: vulnerability exploitation now top initial-access vector at 38 %; KEV median time to listing collapses to 5 days"
summary: "Rapid7 Labs published its Q1 2026 Threat Landscape Report on 2026-05-21 covering January–March 2026 IR data; the GlobeNewswire release accompanied the post the same day. The findings that change what a Swiss/EU public-sector SOC should prioritise:"
discovered_at: "2026-05-23T05:00:08Z"
event_date: null
run_id: 2026-05-23-852c21c8
priority: notable
immediate_action: null
tags:
  - vulnerabilities
  - ransomware
  - nation-state
  - ai-abuse
regions:
  - global
sectors:
  - public-sector
entities:
  - "report:rapid7-q1-2026-threat-landscape-report-vulnerability-exploitation-top-iav"
  - "actor:thegentlemen"
  - "actor:akira"
cves: []
sources:
  - url: "https://www.rapid7.com/blog/post/tr-q1-2026-threat-landscape-report-geopolitics-ransomware/"
    publisher: Rapid7 Q1 2026 Threat Landscape Report
    role: primary
  - url: "https://www.globenewswire.com/news-release/2026/05/21/3299378/36514/en/Rapid7-Q1-2026-Threat-Landscape-Report-Finds-Vulnerability-Exploitation-Overtakes-Social-Engineering-as-the-Top-Initial-Access-Vector.html"
    publisher: GlobeNewswire press release
    role: corroborating
closed_sources: []
evidence: []
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions: []
migrated_from: briefs/2026-05-23.md
---

Rapid7 Labs published its [Q1 2026 Threat Landscape Report](https://www.rapid7.com/blog/post/tr-q1-2026-threat-landscape-report-geopolitics-ransomware/) on 2026-05-21 covering January–March 2026 IR data; the [GlobeNewswire release](https://www.globenewswire.com/news-release/2026/05/21/3299378/36514/en/Rapid7-Q1-2026-Threat-Landscape-Report-Finds-Vulnerability-Exploitation-Overtakes-Social-Engineering-as-the-Top-Initial-Access-Vector.html) accompanied the post the same day. The findings that change what a Swiss/EU public-sector SOC should prioritise:

- **Vulnerability exploitation accounted for 38 % of confirmed initial-access vectors, overtaking social engineering (24 %)** in Rapid7's Q1 2026 dataset. The implication: edge / perimeter patch SLAs and exposure management now drive blast-radius more than awareness training does.
- **More than 50 % of actively exploited vulnerabilities in Q1 2026 were zero-click, network-facing flaws** requiring no authentication or user interaction. The defensive prioritisation gradient sharpens: pre-auth network-facing CVEs > authenticated CVEs > anything user-interaction-dependent.
- **Median time from public disclosure to CISA KEV listing fell from 8.5 days to 5.0 days.** Operators of EU/CH public-sector estates running on monthly patch windows lose ground every cycle; the report frames this as faster AI-assisted N-day weaponisation. PD-13 still applies — the KEV addition is the *exploitation-confirmation* signal, not a US-only compliance deadline — but the window between "vendor publishes" and "expect attempts" has narrowed materially.
- **Exploited vulnerabilities averaged 1.8 million mentions across forums, blogs and social media** before operational targeting, making chatter spikes a leading indicator of imminent exploitation waves.
- **SQL injection became the most-exploited vulnerability class in Q1 2026**, validating the Drupal CVE-2026-9082 story above as part of a broader shift.
- **RMM tool abuse accounted for 22.9 % of observed threat activity, ClickFix-style social engineering 18.8 %** — both worth re-checking on EDR detection coverage in EU/CH environments where ClickFix browser drive-by is less culturally familiar than in U.S. consumer markets.

The report also covers a geopolitical layer (Iranian, Russian and Chinese campaigns synchronised with Middle East military escalation; tools mentioned include BPFDoor and ModeloRAT) and ransomware fragmentation (Qilin leads at 357 leak-site posts, The Gentlemen 206, Akira 174; pure-extortion without encryption continues to grow). Per PD-9 this is the dedicated treatment of the report; specific findings will be cited as context in future briefs rather than re-summarised.
