Radware H1 2026 Global Threat Report Shows Web DDoS Attacks Jump More Than 110% as Cyber Threats Accelerate
Radware’s H1 2026 threat report highlights accelerating DDoS, zero-day exploitation, and AI-driven risks outpacing organizational visibility and control.
Rhea-AI Summary
Radware (RDWR) released its H1 2026 Global Threat Analysis Report, showing Web DDoS attacks up 110.6% versus H1 2025 and 36.3% versus H2 2025.
Web DDoS mitigations in H1 already reached nearly 83% of 2025’s full-year volume, and a straight-line extrapolation suggests a potential 166% year-over-year rise in 2026, with North America facing the highest projected growth. Network DDoS attacks averaged 110 per customer per day, 36.6% above the 2025 baseline, dominated by direct-path UDP floods. Malicious web application and API transactions rose 104% over 2025, exceeding 14,000 per application per day, with vulnerability exploitation making up 62.1% of such attacks and more than 80% of vulnerabilities exploited before official CVE announcement.
Survey data shows 77% of organizations deploying AI agents but only 17.2% claiming full visibility, and widespread under-documentation of internal APIs.
Positive
- None.
Negative
- None.
Key Figures
- Web DDoS activity change
- 110.6%
- H1 2026 versus H1 2025
- 2025 mitigation volume reached
- Nearly 83%
- H1 2026 Web DDoS mitigations versus all of 2025
- Network DDoS attacks
- 110 attacks per customer per day
- H1 2026 average; 36.6% above the 2025 baseline
- Malicious application and API transactions
- 104%
- Increase over 2025 levels
- Malicious transactions per application
- More than 14,000 per day
- H1 2026
- Vulnerability exploitation share
- 62.1%
- Share of recorded web application and API attacks
- CVE-to-exploitation timing
- Below zero
- Mean time from official CVE announcement to first detected attack in H1 2026
- Zero-day exploitation rate
- More than 80%
- Vulnerabilities exploited before official CVE announcement
Historical Context
-
Survey linked AI and API adoption with limited visibility and application security gaps.
24h Move is the share-price change in the day after each event; other market factors may also have contributed.
Key Terms
ddos technical
common vulnerabilities and exposures technical
zero-day exploitation technical
udp floods technical
AI-generated analysis. How Rhea-AI works. Not financial advice.
Malicious web application and API transactions increase
AI accelerates vulnerability discovery; attackers exploit flaws before they are publicly announced
MAHWAH, N.J., Sept. 09, 2026 (GLOBE NEWSWIRE) -- Radware® (NASDAQ: RDWR), a global leader in AI and application security and delivery solutions for multi-cloud environments, today released its H1 2026 Global Threat Analysis Report, revealing a sharp escalation in cyberattack activity across network and application layers during the first six months of the year. The new report analyzes data from Radware’s cloud and managed security services and research from its threat intelligence team, highlighting the increasing speed and scale of DDoS attacks, vulnerability exploitation and AI-driven threats facing organizations worldwide.
In the H1 2026 report:
Web DDoS Attack Activity Skyrockets
Web DDoS attacks surged
- Attack Volume: If attack volumes continue at the same pace, based on a straight-line extrapolation of H1 2026 data, Web DDoS attacks could increase by approximately
166% year over year in 2026. - Geographic Targets: Based on H1 2026 trends, North America is estimated to see the highest projected growth in Web DDoS attacks in 2026 at approximately
190% , compared with an estimated60% in EMEA,39% in Central and Latin America (CALA), and27% in APAC, assuming current-pace conditions continue through year-end.
Network DDoS Attacks Intensify
Network-layer DDoS attacks reached an average of 110 attacks per customer per day during H1 2026, a
- Attack Vectors: Direct-path User Datagram Protocol (UDP) floods, which overwhelm targets with traffic, accounted for
73% of total mitigated packets and more than80% when combined with fragmented UDP traffic. - Industry Targets: The technology sector accounted for
59.4% of all network DDoS attacks, averaging 509 attacks per customer per day. Financial services followed, accounting for20.8% of network attacks. - Geographic Targets: North America absorbed the largest share of network DDoS attacks at
43.1% , while the Middle East recorded the highest attack frequency, averaging 520 attacks per customer per day.
Application and API Attacks Double
Malicious web application and API transactions increased
- Vulnerability Exploitation: Vulnerability exploitation accounted for
62.1% of all recorded web application and API attacks. - Geographic Targets: North America accounted for
79.5% of all global malicious web application and API transactions.
Vulnerability Exploitation Outpaces Defenders
The window between vulnerability disclosure and active exploitation has narrowed dramatically. The mean time from official Common Vulnerabilities and Exposures (CVE) announcement to the first detected attack in the wild dropped to below zero compared with a mean of 21.5 days post-disclosure in 2025 and 53 days in 2024, based on Radware's threat intelligence data.
- Zero-Day Exploitation: The zero-day rate surpassed
80% , meaning more than four out of five vulnerabilities were exploited before their official CVE announcement.
AI Accelerates Cybersecurity Risks
Autonomous AI systems are creating new attack vectors and accelerating vulnerability discovery. Local AI agents that operate continuously on user devices can access systems, execute tasks, call APIs and autonomously download software dependencies, creating risks ranging from prompt injection to software supply chain attacks.
Advanced AI models are also accelerating attack execution. The report highlights how frontier models can use semantic reasoning and vulnerability chaining to identify flaws that have escaped years of human review and traditional security testing. At the same time, increasingly capable open-weight models are making advanced offensive capabilities more broadly accessible.
- AI Agent Adoption: According to Radware's survey research,
77% of organizations are actively deploying or implementing AI agents and autonomous workflows, yet only17.2% report full visibility into the AI agents operating in their environments. - API Development: According to Radware's survey research, more than
70% of organizations increased their use of internally developed APIs over the past year, and81.2% now push production API updates at least weekly. - API Visibility: Despite the rapid pace of development, Radware's survey research found that only
6.9% of organizations fully document their internal APIs, while43% document less than70% of them.
“Attackers are increasingly operating at machine speed — launching direct-path DDoS attacks, exploiting vulnerabilities and using agentic AI to automate and speed up their attacks,” said Pascal Geenens, vice president of threat intelligence at Radware. “At the same time, organizations are rapidly deploying AI agents and APIs without complete visibility into their expanding attack surfaces. The growing gap between the speed of attacks and the ability of organizations to detect and respond to them is fundamentally changing the threat landscape.”
Bad Bot Activity Continues to Rise
Bad bot activity remained elevated in H1 2026, reaching nearly
- Geographic Targets: North America accounted for
50.1% of global bad bot activity, followed by APAC at23.2% .
Hacktivism Tracks Geopolitical Conflict
Geopolitical conflict continued to dictate hacktivist DDoS activity during the first half of 2026. While overall public attack claims entered a multi-quarter contraction after peaking in Q2 2025, activity surged in direct response to military events, including a
- Regional Concentration: Europe remained the primary target, accounting for
48% of all hacktivist DDoS attack claims. - Nation and Industry Targets: Israel was the most targeted country, accounting for
16.9% of claimed attacks, followed by Ukraine (8.4% ) and the United States (7.7% ). Government remained the most targeted industry at37.2% of all claims. - Most Active Threat Actor: Pro-Russian threat collectives continued to dominate hacktivist activity. NoName057(16) alone generated
40.5% of all recorded claims in H1 2026.
Radware’s complete H1 2026 Global Threat Analysis Report can be downloaded here.
Radware Webinar on H1 2026 Global Threat Analysis Report
Radware will host a webinar on October 1, 2026, at 11:00am EDT on The Automated Tipping Point: AI Agents, Zero-Day Exploitation and the H1 2026 Threat Landscape, where Pascal Geenens, vice president of threat intelligence at Radware, will discuss the report and the network, application, AI and hacktivist threat trends shaping the first half of 2026.
Security leaders and researchers are invited to attend and explore the report and its data on cyberattack activity during H1 2026.
Radware conducts threat research on behalf of the wider cybersecurity community, helping equip security professionals with timely insights into attacker techniques, tools, and emerging threat trends. Research, including technical breakdowns and defense recommendations, is available at Radware’s Security Research Center.
THIS PRESS RELEASE AND THE RADWARE H1 2026 GLOBAL THREAT REPORT ARE PROVIDED FOR INFORMATIONAL PURPOSES ONLY. THESE MATERIALS ARE NOT INTENDED TO BE AN INDICATOR OF RADWARE'S BUSINESS PERFORMANCE OR OPERATING RESULTS FOR ANY PRIOR, CURRENT OR FUTURE PERIOD.
Safe Harbor Statement
This press release contains “forward-looking statements” within the meaning of the Private Securities Litigation Reform Act of 1995 and other U.S. securities laws. Any forward-looking statements made herein that are not statements of historical fact, including statements about Radware’s plans, objectives, expectations, beliefs, projections, future financial performance, business strategies, market opportunities, and developments in our industry, are forward-looking statements. In some cases, forward-looking statements can be identified by words such as “believe,” “expect,” “anticipate,” “intend,” “estimate,” “plan,” “project,” “forecast,” “target,” and similar expressions, as well as future or conditional verbs such as “will,” “should,” “would,” “may,” and “could.” For example, when we say in this press release that, based on a straight-line extrapolation of H1 2026 data, Web DDoS attacks could increase by approximately
Because such statements deal with future events, they are subject to various risks and uncertainties that could cause actual results to differ materially from those expressed or implied in such forward-looking statements. Factors that could cause or contribute to such differences include, but are not limited to: the impact of global market and economic conditions; our dependence on independent distributors; disruptions in our supply chain, including shortages of components or manufacturing capacity; our reliance on a limited number of vendors; our ability to attract, train and retain qualified personnel; intense competition in the cybersecurity and application delivery markets; our ability to develop new solutions and enhance existing solutions; risks related to defects, vulnerabilities or failures in our products or services, including cybersecurity incidents affecting our systems or those of our customers; risks associated with the use of artificial intelligence technologies, including evolving regulatory frameworks, litigation exposure and reputational considerations; risks related to our information technology systems, including failures, disruptions or security breaches; outages, interruptions, or delays in hosting or cloud-based services; risks related to the interoperability of our products; risks associated with our global operations; and geopolitical risks, including instability in the Middle East and Israel.
These factors are not exhaustive. For a more detailed description of the risks and uncertainties affecting Radware, please refer to Radware’s Annual Report on Form 20-F and other reports filed with or furnished to the Securities and Exchange Commission (SEC) from time to time.
Forward-looking statements speak only as of the date on which they are made, and, except as required by applicable law, Radware undertakes no obligation to update or revise any forward-looking statements to reflect events or circumstances after the date of such statements. Radware’s public filings are available from the SEC’s website at www.sec.gov or on Radware’s website at www.radware.com.
About Radware
Radware® (NASDAQ: RDWR) is a global leader in application security and delivery solutions for multi-cloud environments. The company’s cloud application, infrastructure, API, and AI security solutions use AI-driven algorithms for precise, behavior-based, real-time protection against sophisticated web, application, and DDoS attacks, API abuse, business logic threats, and malicious bots. Radware delivers end-to-end API security, including discovery, posture management, testing, and runtime protection, along with advanced protection for AI agents and models. Enterprises and carriers worldwide rely on Radware to address evolving cyberthreats, protect their brands and business operations, and reduce costs. For more information, please visit the Radware website.
Radware encourages you to join our community and follow us on: Facebook, LinkedIn, Radware Blog, X, and YouTube.
©2026 Radware Ltd. All rights reserved. Any Radware products and solutions mentioned in this press release are protected by trademarks, patents, and pending patent applications of Radware in the U.S. and other countries. For more details, please see: https://www.radware.com/LegalNotice/. All other trademarks and names are property of their respective owners.
Radware believes the information in this document is accurate in all material respects as of its publication date. However, the information is provided without any express, statutory, or implied warranties and is subject to change without notice.
The contents of any website or hyperlinks mentioned in this press release are for informational purposes and the contents thereof are not part of this press release.
Media Contact:
Gina Sorice
GinaSo@radware.com
Investor Contact:
Yisca Erez
YiscaE@radware.com
A photo accompanying this announcement is available at https://www.globenewswire.com/NewsRoom/AttachmentNg/674f6eef-72b1-4fa8-9f89-5566c52e6a2e
FAQ
What trends did Radware identify in vulnerability exploitation and zero-day attacks?
Radware reports that the mean time from official CVE disclosure to the first detected attack in the wild dropped below zero days in H1 2026, compared with 21.5 days in 2025 and 53 days in 2024. The company also found that the zero-day exploitation rate surpassed 80%, meaning more than four out of five vulnerabilities were attacked before their official CVE announcement.
How are organizations using AI agents and what visibility do they report?
According to Radware’s survey research, 77% of organizations are actively deploying or implementing AI agents and autonomous workflows, but only 17.2% say they have full visibility into the AI agents operating in their environments.
What did the report find about internal API development and documentation practices?
Radware’s survey research indicates that more than 70% of organizations increased their use of internally developed APIs over the past year, and 81.2% push production API updates at least weekly. Despite this pace, only 6.9% of organizations fully document their internal APIs, while 43% document less than 70% of them.
What does the report say about hacktivist DDoS activity and primary targets?
The report links hacktivist DDoS activity to geopolitical conflict, noting a 103% month-over-month increase in March 2026 aligned with reported military events in the Middle East. Europe accounted for 48% of hacktivist DDoS attack claims, with Israel (16.9%), Ukraine (8.4%), and the United States (7.7%) the most targeted countries. Government entities made up 37.2% of claims, and pro-Russian collective NoName057(16) alone generated 40.5% of recorded claims in H1 2026.
When is Radware’s webinar on the H1 2026 Global Threat Analysis Report?
Radware plans to host a webinar titled “The Automated Tipping Point: AI Agents, Zero-Day Exploitation and the H1 2026 Threat Landscape” on October 1, 2026, at 11:00am EDT. Pascal Geenens, Radware’s vice president of threat intelligence, will discuss the report and the network, application, AI, and hacktivist threat trends observed in the first half of 2026.
How does Radware position the threat report in relation to its business performance?
The company states that the press release and the Radware H1 2026 Global Threat Report are provided for informational purposes only and are not intended to indicate Radware’s business performance or operating results for any prior, current, or future period.