Stocktitan Rapid7 Reports Vulnerability Exploitation Surpasses Social Engineering in Q1 2026
Article Content
- •Vulnerability exploitation now accounts for 38% of incident response cases.
- •Half of exploited vulnerabilities were zero-click, requiring no user interaction.
- •Median time from disclosure to CISA KEV inclusion has decreased to 5 days.
Rapid7's Q1 2026 Threat Landscape Report reveals that vulnerability exploitation has become the leading initial access vector, accounting for 38% of incident response cases. This marks a significant shift from social engineering, which accounted for 24%. The report highlights that half of the actively exploited vulnerabilities were zero-click, network-facing issues, allowing attackers direct access without user interaction. The median time from public disclosure to inclusion in CISA's Known Exploited Vulnerabilities (KEV) catalog decreased from 8.5 days to 5.0 days for high and critical vulnerabilities. SQL injection was identified as the most exploited vulnerability type, while fragmented ransomware activity was led by the Qilin group. The findings emphasize the growing role of AI in cyberattacks, compressing response times for defenders. Security teams are urged to prioritize rapid identification and remediation of exposed systems to mitigate risks. Overall, the report underscores the evolving threat landscape driven by AI and sophisticated exploitation methods.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (6)
Following this threat?
Track Qilin in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
SonicWall SMA1000 Faces Critical Zero-Day Exploitation SonicWall disclosed two critical vulnerabilities in its SMA1000 series appliances, CVE-2026-83548 and CVE-2026-83549, which are being actively exploited. CVE-2026-83548 is a pre-authentication server-side request forgery (SSRF) vulnerability rated 10.0 on the CVSS scale, allowing unauthenticated attackers to access…