The window for responding to newly disclosed security flaws is getting shorter. Exploit code can appear quickly, exploitability can be tested soon after disclosure, and organizations have a growing number of weaknesses to sort through. Rapid7’s Q2 2026 Threat Landscape Report counted 8,539 high- and critical-severity vulnerability disclosures, twice the number recorded a year earlier. Source: Rapi

The volume of high- and critical-severity vulnerability disclosures has doubled in the past year, with 8,539 recorded in Q2 2026, according to a recent industry report. This surge is intensifying pressure on security teams, who must prioritize which flaws to address immediately, often contending with a rapidly shrinking window between disclosure and exploit weaponization.
The report highlights that the gap between a patch's availability and an exploit's weaponization has collapsed to near zero. This is exacerbated by a 76% increase in newly disclosed vulnerabilities with publicly available proof-of-concept code compared to Q2 2025. This readily available code makes it easier for attackers to test and weaponize new weaknesses.
A significant concern is the prevalence of network-exploitable vulnerabilities that require no authentication or user interaction. These accounted for 62% of newly exploited vulnerabilities tracked during the quarter, representing an increase from the previous year. Such flaws offer attackers a direct route into vulnerable systems without needing credentials or user engagement.
Internet-facing devices, including VPN systems, remote access gateways, web servers, and routers, are particularly susceptible in this environment. When these devices run vulnerable software accessible from the internet, they become prime entry points for attackers. Organizations are advised to maintain accurate inventories of externally accessible systems, identify reachable vulnerabilities, and enforce authentication on exposed endpoints to mitigate this risk.
Beyond technical exploits, social engineering remains a persistent threat. Fake CAPTCHA and ClickFix techniques constituted 31.8% of observed incident response cases in Q2 2026. These tactics trick users into running malicious commands by presenting seemingly benign instructions. Attackers are also leveraging platforms like Microsoft Teams for social engineering, using familiar workplace communication channels to approach employees.
Once initial access is gained, attackers typically focus on escalating privileges and moving deeper into networks. Common techniques include credential harvesting, abusing remote management tools, and exploiting public-facing software. Ransomware continues to be a significant threat, with the United States recording 881 listed victims during the quarter, far exceeding other countries. Business services and healthcare were the most targeted sectors.
State-aligned groups are also conducting sustained campaigns. Russian-linked APT28 activity included exploiting small office and home office routers for DNS hijacking, potentially exposing authentication tokens and passwords. Iranian groups targeted industrial control and operational technology systems in the United States.
Underground markets further complicate the threat landscape, with exploit and access listings observed across 20 sources. Most vulnerabilities traded in these markets already have publicly available proof-of-concept code, and some are listed in the U.S. Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog. A large majority of these are also network-exploitable vulnerabilities requiring no authentication or user interaction.
Internet-facing edge appliances, such as SSL-VPN systems, RDP gateways, and web servers, remain a critical area of concern. Recommended measures include inventorying and patching these systems, rotating credentials, and enforcing multi-factor authentication on all remote-access paths. Security teams are encouraged to cross-reference vulnerability disclosure spikes with their asset inventories, prioritizing based on internet exposure, reachability, and potential network access paths, rather than treating all newly disclosed vulnerabilities with equal urgency.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.