Skip to content
Rapid7 Reports Vulnerability Exploitation Surpasses Social Engineering in Q1 2026

Rapid7 Reports Vulnerability Exploitation Surpasses Social Engineering in Q1 2026

First seen 22 May 2026, 07:56 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster May 23, 2026 at 06:55 UTC
  • Vulnerability exploitation now accounts for 38% of incident response cases.
  • Half of exploited vulnerabilities were zero-click, requiring no user interaction.
  • Median time from disclosure to CISA KEV inclusion has decreased to 5 days.

Rapid7's Q1 2026 Threat Landscape Report reveals that vulnerability exploitation has become the leading initial access vector, accounting for 38% of incident response cases. This marks a significant shift from social engineering, which accounted for 24%. The report highlights that half of the actively exploited vulnerabilities were zero-click, network-facing issues, allowing attackers direct access without user interaction. The median time from public disclosure to inclusion in CISA's Known Exploited Vulnerabilities (KEV) catalog decreased from 8.5 days to 5.0 days for high and critical vulnerabilities. SQL injection was identified as the most exploited vulnerability type, while fragmented ransomware activity was led by the Qilin group. The findings emphasize the growing role of AI in cyberattacks, compressing response times for defenders. Security teams are urged to prioritize rapid identification and remediation of exposed systems to mitigate risks. Overall, the report underscores the evolving threat landscape driven by AI and sophisticated exploitation methods.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 120d ago How this analysis works

Timeline

2026-05-21
Rapid7 Q1 2026 Threat Landscape Report released
The report indicates vulnerability exploitation surpassed social engineering as the top access vector, highlighting AI's role in cyberattacks.
Stocktitan
2026-05-21
Key findings on zero-click vulnerabilities
The report found that 50% of actively exploited vulnerabilities were zero-click, allowing direct access to systems without user action.
Markets.Ft
2026-05-21
Median remediation time decreases
The median time for high-severity vulnerabilities from disclosure to CISA KEV inclusion fell from 8.5 days to 5.0 days.
Markets.Ft

More articles in this cluster (6)

Following this threat?

Track Qilin in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed