Powered by MOMENTUMMEDIA
For breaking news and daily updates, subscribe to our newsletter

Report: AI-driven disclosures are collapsing the window for defenders to patch vulnerabilities

Rapid7 warns that soaring vulnerability volumes and faster weaponisation are rendering traditional patching cycles increasingly ineffective.

Wed, 19 Aug 2026
Report: AI-driven disclosures are collapsing the window for defenders to patch vulnerabilities

Security teams are facing a rapidly shrinking window to respond to newly disclosed vulnerabilities, according to Rapid7’s latest Quarterly Threat Landscape Report.

High- and critical-vulnerability disclosures doubled year-on-year to 8,539, while newly exploited vulnerabilities increased by up to 40 per cent, highlighting the growing gap between spotting a flaw and stopping attackers from weaponising it.

The report found that 62 per cent of newly exploited vulnerabilities were zero-click flaws that could be exploited remotely without authentication or user interaction.

 
 

Meanwhile, critical vulnerability disclosures rose 21 per cent quarter-on-quarter, publicly available proof-of-concept code increased 12 per cent from the previous quarter and 76 per cent year-on-year, and disclosures involving missing authentication jumped 247 per cent year-on-year.

According to Rapid7, these trends make reliance on static CVSS scores and periodic patch cycles increasingly untenable. Defenders now need to prioritise exposures based on their likelihood of being exploited rather than simply working through an ever-growing list of CVEs.

"We’ve turned vulnerability management into a high-stress game of CVE bingo,” warned Christiaan Beek, Vice President of Rapid7 Labs.

“High-severity disclosures exploded from 4,268 to 8,539 year-over-year driven by automated discovery tools and AI models like Anthropic’s Mythos. But finding a candidate bug isn't the same as weaponising an exploit. Confirmed wild exploitation actually dropped slightly to 40 CVEs.

“Everyone loves an apocalypse narrative because it sells software, but AI isn't a magical, autonomous cyber-weapon yet; it’s just a hyper-efficient scanner. The real story isn't that AI found thousands of bugs; it’s that defenders are burning out trying to patch internal, unreachable code while ignoring the obvious front doors attackers actually walk through."

The spike in easily exploited vulnerabilities is also making hackers' work that much easier, according to Beek.

"Attackers are lazy, efficient professionals; they obey the path of least resistance,” Beek said.

“Why would an adversary waste months building a complex, multi-stage exploit chain when organisations are routinely leaving internet-facing management interfaces completely unauthenticated? We are leaving the front doors unlatched and then acting surprised when
someone turns the handle."

You can read the full report here.

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.
Tags: