The volume of high- and critical-severity vulnerability disclosures has doubled in the past year, with 8,539 recorded in Q2 2026, according to a recent industry report. This surge is intensifying pressure on security teams, who must prioritize which flaws to address immediately, often contending with a rapidly shrinking window between disclosure and exploit weaponization.
The report highlights that the gap between a patch's availability and an exploit's weaponization has collapsed to near zero. This is exacerbated by a 76% increase in newly disclosed vulnerabilities with publicly available proof-of-concept code compared to Q2 2025. This readily available code makes it easier for attackers to test and weaponize new weaknesses.
A significant concern is the prevalence of network-exploitable vulnerabilities that require no authentication or user interaction. These accounted for 62% of newly exploited vulnerabilities tracked during the quarter, representing an increase from the previous year. Such flaws offer attackers a direct route into vulnerable systems without needing credentials or user engagement.
Internet-facing devices, including VPN systems, remote access gateways, web servers, and routers, are particularly susceptible in this environment. When these devices run vulnerable software accessible from the internet, they become prime entry points for attackers. Organizations are advised to maintain accurate inventories of externally accessible systems, identify reachable vulnerabilities, and enforce authentication on exposed endpoints to mitigate this risk.
Beyond technical exploits, social engineering remains a persistent threat. Fake CAPTCHA and ClickFix techniques constituted 31.8% of observed incident response cases in Q2 2026. These tactics trick users into running malicious commands by presenting seemingly benign instructions. Attackers are also leveraging platforms like Microsoft Teams for social engineering, using familiar workplace communication channels to approach employees.
Once initial access is gained, attackers typically focus on escalating privileges and moving deeper into networks. Common techniques include credential harvesting, abusing remote management tools, and exploiting public-facing software. Ransomware continues to be a significant threat, with the United States recording 881 listed victims during the quarter, far exceeding other countries. Business services and healthcare were the most targeted sectors.
State-aligned groups are also conducting sustained campaigns. Russian-linked APT28 activity included exploiting small office and home office routers for DNS hijacking, potentially exposing authentication tokens and passwords. Iranian groups targeted industrial control and operational technology systems in the United States.
Underground markets further complicate the threat landscape, with exploit and access listings observed across 20 sources. Most vulnerabilities traded in these markets already have publicly available proof-of-concept code, and some are listed in the U.S. Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog. A large majority of these are also network-exploitable vulnerabilities requiring no authentication or user interaction.
Internet-facing edge appliances, such as SSL-VPN systems, RDP gateways, and web servers, remain a critical area of concern. Recommended measures include inventorying and patching these systems, rotating credentials, and enforcing multi-factor authentication on all remote-access paths. Security teams are encouraged to cross-reference vulnerability disclosure spikes with their asset inventories, prioritizing based on internet exposure, reachability, and potential network access paths, rather than treating all newly disclosed vulnerabilities with equal urgency.






