Stocktitan
Rapid7 Reports Vulnerability Exploitation Surpasses Social Engineering in Q1 2026
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Rapid7's Q1 2026 Threat Landscape Report reveals that vulnerability exploitation has become the leading initial access vector, accounting for 38% of incident response cases. This marks a significant shift from social engineering, which accounted for 24%. The report highlights that half of the actively exploited vulnerabilities were zero-click, network-facing issues, allowing attackers direct access without user interaction. The median time from public disclosure to inclusion in CISA's Known Exploited Vulnerabilities (KEV) catalog decreased from 8.5 days to 5.0 days for high and critical vulnerabilities. SQL injection was identified as the most exploited vulnerability type, while fragmented ransomware activity was led by the Qilin group. The findings emphasize the growing role of AI in cyberattacks, compressing response times for defenders. Security teams are urged to prioritize rapid identification and remediation of exposed systems to mitigate risks. Overall, the report underscores the evolving threat landscape driven by AI and sophisticated exploitation methods.
Key Points: • Vulnerability exploitation now accounts for 38% of incident response cases. • Half of exploited vulnerabilities were zero-click, requiring no user interaction. • Median time from disclosure to CISA KEV inclusion has decreased to 5 days.