Rapid7 Q1 2026 Threat Landscape Report Finds Vulnerability Exploitation Overtakes Social Engineering as the Top Initial Access Vector
Rapid7 (NASDAQ:RPD) released its Q1 2026 Threat Landscape Report, showing that vulnerability exploitation overtook social engineering as the top initial access vector, driving 38% of incident response cases.
Rhea-AI Summary
Rapid7 (NASDAQ:RPD) released its Q1 2026 Threat Landscape Report, showing that vulnerability exploitation overtook social engineering as the top initial access vector, driving 38% of incident response cases. Social engineering accounted for 24% and compromised accounts 14%.
Half of actively exploited CVEs were zero-click, network-facing, requiring no authentication or user interaction. High and critical vulnerabilities saw the median time from public disclosure to CISA KEV inclusion fall from 8.5 to 5.0 days, highlighting shrinking remediation windows.
The report also notes SQL injection as the most exploited vulnerability type, fragmented ransomware activity led by Qilin, and abused Remote Monitoring and Management tools representing 22.9% of observed threat activity.
Positive
- None.
Negative
- None.
Details
News Market Reaction – RPD
In the May 21 session, RPD declined 3.15%, reflecting a moderate negative market reaction.
Data tracked by StockTitan Argus on the day of publication.
Key Figures
- Exploitation share
- 38%
- Share of incident response cases from vulnerability exploitation in Q1 2026
- Social engineering share
- 24%
- Share of incident response cases from social engineering in Q1 2026
- Compromised accounts share
- 14%
- Share of incident response cases from compromised accounts in Q1 2026
- Median KEV timeline 2025
- 8.5 days
- Median time from disclosure to CISA KEV for high/critical vulns (prior period)
- Median KEV timeline Q1 2026
- 5.0 days
- Median time from disclosure to CISA KEV for high/critical vulns in Q1 2026
- Public mentions per vuln
- 1.8 million
- Average public mentions of exploited vulnerabilities across online sources
- Qilin ransomware posts
- 357
- Number of leak-site posts attributed to Qilin in Q1 2026
- RMM threat share
- 22.9%
- Share of observed activity from abused Remote Monitoring and Management tools
Historical Context
-
Launch of Cyber GRC Early Access Program with 360 Advanced.
-
Early access Cyber GRC program built on Command Platform.
-
Participation in J.P. Morgan and William Blair investor conferences.
-
Reported Q1 2026 financials and Kenzo Security acquisition.
-
Announcement of schedule for Q1 2026 earnings release.
24h Move is the share-price change in the day after each event; other market factors may also have contributed.
Key Terms
zero-click technical
cves technical
sql injection technical
os command injection technical
ransomware technical
remote monitoring and management (rmm) tools technical
dark web technical
incident response technical
AI-generated analysis. How Rhea-AI works. Not financial advice.
New research highlights how AI-driven exploitation, zero-click vulnerabilities, and fragmented ransomware operations are reshaping cyber risk
BOSTON, May 21, 2026 (GLOBE NEWSWIRE) -- Rapid7, Inc. (NASDAQ: RPD), a global leader in AI-powered managed cybersecurity operations, released its Q1 2026 Threat Landscape Report, examining trends in vulnerability exploitation, ransomware activity, and cybercriminal infrastructure. The report found that vulnerability exploitation surpassed social engineering as the leading initial access vector, accounting for
Reinforcing this trend, half of vulnerabilities actively exploited in the wild during Q1 were zero-click, network-facing issues requiring no authentication or user interaction, giving attackers direct access to exposed systems without relying on human action. The finding reinforces trends identified in Rapid7’s 2026 Annual Global Threat Landscape Report, which found that exploitation timelines continue to shrink: among high- and critical-severity vulnerabilities, the median time from public disclosure to inclusion in CISA’s Known Exploited Vulnerabilities (KEV) catalog fell from 8.5 days to 5.0 days.
"We've spent years building a security culture around humans being the weakest link, but our Q1 findings show AI is quietly rewriting that equation," said Raj Samani, SVP and Chief Scientist at Rapid7. "Attackers are increasingly bypassing user interaction altogether, prioritizing direct access to exposed infrastructure and dramatically narrowing the window defenders have to respond."
Drawing on select tracked CVEs, MDR incident response data, ransomware leak-site intelligence, and dark web telemetry, the report highlights evolving exploitation patterns, ransomware activity, and changes in attacker infrastructure.
Key findings include:
- Vulnerability exploitation was the leading initial access vector in MDR data: Exploitation accounted for
38% of incident response cases, followed by social engineering (24% ) and compromised accounts (14% ). - Zero-click, network-facing vulnerabilities dominated exploited CVEs: Half of vulnerabilities actively exploited in the wild during Q1 required no authentication or user interaction, enabling direct access to exposed systems.
- Public discussion preceded exploitation activity: Exploited vulnerabilities averaged 1.8 million mentions across blogs, forums, and social media, indicating that widely discussed vulnerabilities can quickly become operational targets.
- SQL injection became the most exploited vulnerability type: SQL injection overtook OS command injection in Q1, reflecting attacker focus on common, broadly distributed web application weaknesses.
- Ransomware activity remained fragmented across groups: Qilin led leak-site activity with 357 posts, followed by The Gentlemen (206) and Akira (174), indicating ransomware activity remained fragmented across operators.
- Abused Remote Monitoring and Management (RMM) tools were the most prevalent threat category: RMM tools accounted for
22.9% of observed activity, followed by ClickFix (18.8% ) and Windows Native Scripts (10.4% ).
What this means for security operations
As exploitation timelines continue to shrink, security teams face increasing pressure to identify, prioritize, and remediate exposed systems before attackers can operationalize vulnerabilities at scale.
“Q1 shows how quickly exposed systems can become operational targets,” said Christiaan Beek, Vice President of Cyber Intelligence at Rapid7. “Security teams can’t apply the same level of investigation and response across every signal when attackers are consistently prioritizing what they can reach and exploit. That gap is where risk accumulates.”
To read a full copy of the report, visit https://www.rapid7.com/research/report/threat-landscape-report-2026-q1/ .
About the Rapid7 Q1 2026 Threat Landscape Report
The Rapid7 Threat Landscape Report is a quarterly analysis of global adversary behavior drawn from the company’s managed detection and response operations, vulnerability intelligence platforms, and threat research telemetry. The Q1 2026 edition examines the impact of vulnerability exploitation, geopolitical cyber activity, ransomware evolution, and cybercriminal infrastructure.
About Rapid7
Rapid7, Inc. (NASDAQ: RPD) is a global leader in AI-powered managed cybersecurity operations, trusted to advance organizations’ cyber resilience. Open and extensible, the Rapid7 Command Platform integrates security data, enriching it with AI, threat intelligence, and 25 years of expertise and innovation to reduce risk and disrupt attackers. As a recognized leader in preemptive managed detection and response (MDR), Rapid7 unifies exposure and detection to transform the cybersecurity operations of more than 11,500 customers worldwide. For more information, visit our website, check out our blog, or follow us on LinkedIn or X.
Rapid7 Media Relations
Alice Randall
Director, Global Communications
press@rapid7.com
(857) 216-7804
Rapid7 Investor Contact
Matt Wells
Vice President, Investor Relations
investors@rapid7.com
(617) 865-4277
FAQ
AI-generated questions and answers. How Rhea-AI works. Not financial advice.