STOCK TITAN

Rapid7 Finds Nearly Two-Thirds of Vulnerabilities Exploited in Q2 2026 Required No User Interaction to Initiate

(Moderate)
(Very Negative)
Tags

Rapid7 (NASDAQ: RPD) released its Q2 2026 Quarterly Threat Landscape Report, highlighting that newly exploited vulnerabilities surged from 8% to 40% and that 62% of newly exploited flaws required no user interaction or authentication, breaking traditional, periodic patching models.

According to Rapid7, high and critical vulnerability disclosures doubled year over year to 8,539, critical vulnerabilities rose 21% quarter over quarter, and publicly available proof-of-concept code increased 12% QoQ and 76% YoY. Disclosures involving missing authentication climbed 247% YoY, from 45 to 156. The report also tracks ransomware, with the United States recording 881 listed victims versus 99 in Germany, and notes state-aligned activity from Iran, North Korea, and Russia targeting critical infrastructure and enterprise sectors.

Loading...
Loading translation...

Positive

  • None.

Negative

  • None.

Market Reaction – RPD

+1.66% $12.57
15m delay
+1.66% Vs previous close
$12.57 Last Price
$12.46 $12.93 Day Range
$847.56M Market Cap
0.6x Rel. Volume

Following this news, RPD has gained 1.66%, reflecting a mild positive market reaction. Our momentum scanner has triggered 5 alerts so far, indicating moderate trading interest and price volatility. The stock is currently trading at $12.57.

Data tracked by StockTitan Argus (15 min delayed). Upgrade to Gold for real-time data.

Market Context

Rapid7's recent news reactions ranged from -8.33% to 15.16%, placing this threat report in a mixed h...
Analysis

Rapid7's recent news reactions ranged from -8.33% to 15.16%, placing this threat report in a mixed historical context. Moderate short positioning was an additional risk factor to monitor alongside exposure-management relevance.

Key Figures

Newly exploited vulnerabilities: 40% High and critical disclosures: 8,539 Zero-click vulnerabilities: 62% +5 more
8 metrics
Newly exploited vulnerabilities 40% Q2 2026, increased from 8%
High and critical disclosures 8,539 Q2 2026, doubled year-over-year
Zero-click vulnerabilities 62% Share of newly exploited vulnerabilities
Critical vulnerabilities 21% Quarter-over-quarter increase
Proof-of-concept code 12% Quarter-over-quarter increase
Proof-of-concept code 76% Year-over-year increase
Missing-authentication disclosures 247% Year-over-year increase, from 45 to 156
Listed ransomware victims 881 vs. 99 victims United States versus Germany

Historical Context

5 past events · Latest: Aug 12 (Positive)
Pattern 5 events
Date Event Sentiment 24h Move Catalyst
Aug 12 AI governance research Positive -8.3% Research highlighted AI adoption, governance concerns, and human oversight among security professionals.
Aug 10 2Q26 earnings report Positive +15.2% Quarterly results included profitability, cash generation, and updated full-year operating guidance.
Jul 28 Cyber GRC launch Positive -0.1% Rapid7 launched generally available governance, risk, and compliance capabilities.
Jul 14 Earnings date announcement Neutral -5.5% Rapid7 scheduled its second-quarter financial results release and conference call.
Jun 15 Inducement RSU grant Negative -3.4% Rapid7 granted 525,000 restricted stock units under Nasdaq listing rules.

24h Move is the share-price change in the day after each event; other market factors may also have contributed.

Pattern Detected

Rapid7's recent news reactions were mixed, with positive or informational announcements often diverging from the headline sentiment.

Key Terms

cvss, zero-click vulnerabilities, proof-of-concept code, operational technology, +1 more
5 terms
cvss technical
"relying on static CVSS scores and periodic patching is no longer viable"
Common Vulnerability Scoring System (CVSS) is a standardized way to rate the severity of software security flaws on a numeric scale, summarizing how easily a vulnerability can be exploited and how much damage it could cause. For investors, CVSS scores act like a storm severity chart for a company’s digital systems — higher scores signal greater operational, financial and reputational risk, possibly leading to remediation costs, downtime, or regulatory scrutiny that can affect a firm’s value.
zero-click vulnerabilities technical
"Key findings include: Zero-click vulnerabilities increased."
Software or system weaknesses that allow an attacker to compromise a device or account without any action from the user, such as opening a link or clicking a button. Like a locked door that can be opened remotely without the resident doing anything, these flaws can let hackers install malware, steal data, or access networks silently. Investors care because such vulnerabilities can trigger sudden breaches, regulatory scrutiny, remediation costs, and damage to customer trust that affect a company's value.
proof-of-concept code technical
"publicly available proof-of-concept code rose 12% from the previous quarter"
Proof-of-concept code is a short, prototype program written to show that a technical idea, algorithm, or feature can work in practice; it demonstrates feasibility but is not production-ready and typically lacks robustness, security, documentation, and scalability. For investors, it matters because it provides an early, tangible signal of technical risk and plausibility—like a clay model that shows a design can exist—helping to assess whether claimed technology milestones and development timelines are realistic.
operational technology technical
"actively targeting operational technology and industrial control systems"
Operational technology is the physical equipment and specialized software that directly control machines, sensors and processes in factories, energy grids, transportation systems and buildings — think of it as a facility’s control panel and nervous system. Investors care because problems, upgrades or cyberattacks in this area can halt production, raise costs, require large capital spending, or trigger safety and regulatory issues that affect revenue and valuation.
industrial control systems technical
"targeting operational technology and industrial control systems"
A network of hardware and software—such as programmable logic controllers, remote terminal units, and supervisory control systems—that monitor and direct industrial processes like manufacturing lines, power grids, water treatment, and building systems. Think of it as the facility’s nervous system and control panel that keeps machines running, maintains safety limits, and records activity. Because these systems affect production continuity, safety, regulatory compliance and exposure to cyberattacks, their condition and upgrades can influence operational costs, downtime risk and capital spending, all of which matter to investors.

AI-generated analysis. How Rhea-AI works. Not financial advice.

See more from StockTitan in Google Search and AI answers. Adds StockTitan as a preferred source · opens Google
Add on Google

Newly exploited vulnerabilities jumped from 8% to 40% in Q2 2026, outpacing traditional patch cycles

BOSTON, Aug. 18, 2026 (GLOBE NEWSWIRE) -- Rapid7, Inc. (NASDAQ: RPD), a global leader in AI-powered managed cybersecurity operations, today released its Quarterly Threat Landscape Report, revealing that rising vulnerability volumes and faster weaponization are breaking traditional patching models. The findings reinforce that security teams must move beyond static severity scores and prioritize the exposures attackers can realistically exploit.

As AI accelerates flaw discovery, the critical challenge for defenders is no longer just finding bugs - it is acting before adversaries do. According to the report, high and critical disclosures doubled year-over-year to 8,539, with newly exploited vulnerabilities jumping by up to 40%. With the window between disclosure and active exploit collapsing, relying on static CVSS scores and periodic patching is no longer viable.

“Security teams are chasing ghosts if they think they're 'secure' just by closing tickets based on CVSS scores. We're drowning in a deluge of disclosures, and the gap between a patch existing and an exploit being weaponized has collapsed to near zero,” said Christiaan Beek, Vice President, Rapid7 Labs. “If you're still relying on periodic patch cycles while your adversary is automating their kill chain, you aren't managing risk, you're just subsidizing the attackers' R&D. Stop collecting CVEs and start focusing on the exposures that actually matter.”

Key findings include:

  • Zero-click vulnerabilities increased. 62% of newly exploited vulnerabilities were “holy grail” flaws that could be exploited over a network without authentication or user interaction.
  • Weaponization signals accelerated. The volume of critical vulnerabilities increased 21% quarter over quarter, while publicly available proof-of-concept code rose 12% from the previous quarter and 76% year over year, expanding the pool of vulnerabilities attackers can quickly turn into real-world attacks.
  • Missing authentication created a growing attack surface. Disclosures involving missing authentication increased 247% year over year, from 45 to 156.
  • Ransomware remained concentrated but continued expanding geographically. The United States accounted for 881 listed ransomware victims, approximately nine times the 99 recorded in Germany. India and Thailand also entered the quarter’s top 10 countries, indicating that ransomware affiliate programs are extending beyond their historically prominent U.S. and European targets.

The report also documents state-aligned campaigns from Iran, North Korea, and Russia targeting critical infrastructure and enterprise sectors. Key tactics included exploiting SOHO edge routers for DNS hijacking and actively targeting operational technology and industrial control systems.

What this means for security operations
The second quarter of 2026 makes clear that the traditional wait-and-see patch cycle is no longer enough. With vulnerability disclosures surging and attackers increasingly automating discovery, security teams need to focus less on chasing every new flaw and more on reducing exposure that is actually reachable and exploitable. That shift toward evidence-based exposure management is at the heart of a preemptive security approach.

To read a full copy of the report, visit here.

About the Rapid7 Quarterly Threat Landscape Report
The Rapid7 Threat Landscape Report is a quarterly analysis of global adversary behavior drawn from the company’s managed detection and response operations, vulnerability intelligence platforms, and threat research telemetry. The Q2 2026 edition examines accelerating vulnerability disclosure and weaponization, geopolitical cyber activity, evolving social engineering tactics, dark web activities, and ransomware trends.

About Rapid7
Rapid7, Inc. (NASDAQ: RPD) is a global leader in AI-powered managed cybersecurity operations, trusted to advance organizations’ cyber resilience. Open and extensible, the Rapid7 Command Platform integrates security data, enriching it with AI, threat intelligence, and 25 years of expertise and innovation to reduce risk and disrupt attackers. As a recognized leader in preemptive managed detection and response (MDR), Rapid7 unifies exposure and detection to transform the cybersecurity operations of more than 11,500 customers worldwide. For more information, visit our website, check out our blog, or follow us on LinkedIn or X.

Media Contact
Christine Nurnberger
SVP Global Marketing and Growth
press@rapid7.com

Rapid7 Investor Contact
Ryan Flanagan
ICR for Rapid7
investors@rapid7.com
(617) 865-4277


FAQ

What are the key findings from Rapid7’s Q2 2026 Threat Landscape Report (NASDAQ: RPD)?

Rapid7 reports that newly exploited vulnerabilities rose from 8% to 40% in Q2 2026. According to Rapid7, high and critical disclosures doubled year over year to 8,539, while critical vulnerabilities and proof-of-concept code increased significantly, challenging traditional, periodic patch management practices.

How many Q2 2026 vulnerabilities required no user interaction according to Rapid7 (RPD)?

Rapid7 found that 62% of newly exploited Q2 2026 vulnerabilities were zero-click flaws requiring no user interaction or authentication. According to Rapid7, these network-exploitable issues represent a “holy grail” for attackers and illustrate why exposure-based, not score-based, prioritization is increasingly important for defenders.

How did high and critical vulnerability volumes change in Q2 2026 in Rapid7’s report?

Rapid7 reports that high and critical vulnerability disclosures doubled year over year to 8,539 in Q2 2026. According to Rapid7, critical vulnerabilities grew 21% quarter over quarter, while proof-of-concept exploit code rose 12% QoQ and 76% YoY, expanding attackers’ usable toolkit.

What does Rapid7 say about missing authentication vulnerabilities in Q2 2026?

Rapid7 notes that disclosures involving missing authentication rose 247% year over year in Q2 2026, increasing from 45 to 156. According to Rapid7, this growth creates a larger attack surface of easily reachable systems, reinforcing the need to prioritize directly exploitable exposures over general vulnerability counts.