Rapid7 Finds Nearly Two-Thirds of Vulnerabilities Exploited in Q2 2026 Required No User Interaction to Initiate
Rhea-AI Summary
Rapid7 (NASDAQ: RPD) released its Q2 2026 Quarterly Threat Landscape Report, highlighting that newly exploited vulnerabilities surged from 8% to 40% and that 62% of newly exploited flaws required no user interaction or authentication, breaking traditional, periodic patching models.
According to Rapid7, high and critical vulnerability disclosures doubled year over year to 8,539, critical vulnerabilities rose 21% quarter over quarter, and publicly available proof-of-concept code increased 12% QoQ and 76% YoY. Disclosures involving missing authentication climbed 247% YoY, from 45 to 156. The report also tracks ransomware, with the United States recording 881 listed victims versus 99 in Germany, and notes state-aligned activity from Iran, North Korea, and Russia targeting critical infrastructure and enterprise sectors.
Positive
- None.
Negative
- None.
Market Reaction – RPD
Following this news, RPD has gained 1.66%, reflecting a mild positive market reaction. Our momentum scanner has triggered 5 alerts so far, indicating moderate trading interest and price volatility. The stock is currently trading at $12.57.
Data tracked by StockTitan Argus (15 min delayed). Upgrade to Gold for real-time data.
Key Figures
Historical Context
| Date | Event | Sentiment | 24h Move | Catalyst |
|---|---|---|---|---|
| Aug 12 | AI governance research | Positive | -8.3% | Research highlighted AI adoption, governance concerns, and human oversight among security professionals. |
| Aug 10 | 2Q26 earnings report | Positive | +15.2% | Quarterly results included profitability, cash generation, and updated full-year operating guidance. |
| Jul 28 | Cyber GRC launch | Positive | -0.1% | Rapid7 launched generally available governance, risk, and compliance capabilities. |
| Jul 14 | Earnings date announcement | Neutral | -5.5% | Rapid7 scheduled its second-quarter financial results release and conference call. |
| Jun 15 | Inducement RSU grant | Negative | -3.4% | Rapid7 granted 525,000 restricted stock units under Nasdaq listing rules. |
24h Move is the share-price change in the day after each event; other market factors may also have contributed.
Rapid7's recent news reactions were mixed, with positive or informational announcements often diverging from the headline sentiment.
Key Terms
cvss technical
zero-click vulnerabilities technical
proof-of-concept code technical
operational technology technical
industrial control systems technical
AI-generated analysis. How Rhea-AI works. Not financial advice.
Newly exploited vulnerabilities jumped from
BOSTON, Aug. 18, 2026 (GLOBE NEWSWIRE) -- Rapid7, Inc. (NASDAQ: RPD), a global leader in AI-powered managed cybersecurity operations, today released its Quarterly Threat Landscape Report, revealing that rising vulnerability volumes and faster weaponization are breaking traditional patching models. The findings reinforce that security teams must move beyond static severity scores and prioritize the exposures attackers can realistically exploit.
As AI accelerates flaw discovery, the critical challenge for defenders is no longer just finding bugs - it is acting before adversaries do. According to the report, high and critical disclosures doubled year-over-year to 8,539, with newly exploited vulnerabilities jumping by up to
“Security teams are chasing ghosts if they think they're 'secure' just by closing tickets based on CVSS scores. We're drowning in a deluge of disclosures, and the gap between a patch existing and an exploit being weaponized has collapsed to near zero,” said Christiaan Beek, Vice President, Rapid7 Labs. “If you're still relying on periodic patch cycles while your adversary is automating their kill chain, you aren't managing risk, you're just subsidizing the attackers' R&D. Stop collecting CVEs and start focusing on the exposures that actually matter.”
Key findings include:
- Zero-click vulnerabilities increased.
62% of newly exploited vulnerabilities were “holy grail” flaws that could be exploited over a network without authentication or user interaction. - Weaponization signals accelerated. The volume of critical vulnerabilities increased
21% quarter over quarter, while publicly available proof-of-concept code rose12% from the previous quarter and76% year over year, expanding the pool of vulnerabilities attackers can quickly turn into real-world attacks. - Missing authentication created a growing attack surface. Disclosures involving missing authentication increased
247% year over year, from 45 to 156. - Ransomware remained concentrated but continued expanding geographically. The United States accounted for 881 listed ransomware victims, approximately nine times the 99 recorded in Germany. India and Thailand also entered the quarter’s top 10 countries, indicating that ransomware affiliate programs are extending beyond their historically prominent U.S. and European targets.
The report also documents state-aligned campaigns from Iran, North Korea, and Russia targeting critical infrastructure and enterprise sectors. Key tactics included exploiting SOHO edge routers for DNS hijacking and actively targeting operational technology and industrial control systems.
What this means for security operations
The second quarter of 2026 makes clear that the traditional wait-and-see patch cycle is no longer enough. With vulnerability disclosures surging and attackers increasingly automating discovery, security teams need to focus less on chasing every new flaw and more on reducing exposure that is actually reachable and exploitable. That shift toward evidence-based exposure management is at the heart of a preemptive security approach.
To read a full copy of the report, visit here.
About the Rapid7 Quarterly Threat Landscape Report
The Rapid7 Threat Landscape Report is a quarterly analysis of global adversary behavior drawn from the company’s managed detection and response operations, vulnerability intelligence platforms, and threat research telemetry. The Q2 2026 edition examines accelerating vulnerability disclosure and weaponization, geopolitical cyber activity, evolving social engineering tactics, dark web activities, and ransomware trends.
About Rapid7
Rapid7, Inc. (NASDAQ: RPD) is a global leader in AI-powered managed cybersecurity operations, trusted to advance organizations’ cyber resilience. Open and extensible, the Rapid7 Command Platform integrates security data, enriching it with AI, threat intelligence, and 25 years of expertise and innovation to reduce risk and disrupt attackers. As a recognized leader in preemptive managed detection and response (MDR), Rapid7 unifies exposure and detection to transform the cybersecurity operations of more than 11,500 customers worldwide. For more information, visit our website, check out our blog, or follow us on LinkedIn or X.
Media Contact
Christine Nurnberger
SVP Global Marketing and Growth
press@rapid7.com
Rapid7 Investor Contact
Ryan Flanagan
ICR for Rapid7
investors@rapid7.com
(617) 865-4277