Surge in Exploited CVEs and Malware Activity in H1 2026

Surge in Exploited CVEs and Malware Activity in H1 2026

First seen 4 Sep 2026, 13:49 UTC RecordedfutureTechnadu 71.0

Article Content

Browse articles
ThreatCluster

In the first half of 2026, Insikt Group reported 215 actively exploited CVEs, marking a 34% increase from the previous year. Notably, AsyncRAT emerged as the leading malware, with nearly 60,000 unique hashes. The report highlighted a significant rise in NFC-based Android attacks, which surged by 188%. Threat actors continued to exploit known vulnerabilities and legitimate tools, emphasizing the use of remote access trojans (RATs). Microsoft was identified as the vendor with the highest number of exploited vulnerabilities, totaling 40. AI-enabled malware activity became more prominent, although it remained within lower maturity levels. The findings underscore a trend of attackers leveraging established techniques rather than novel methods. Overall, the landscape reflects a growing risk as attackers blend malicious activity with legitimate workflows.

Key Points: • 215 CVEs were actively exploited in H1 2026, a 34% increase from H1 2025. • AsyncRAT led malware activity with around 60,000 unique hashes. • NFC-based Android attacks increased by 188% in early 2026.

Ask AI about this cluster

Timeline

2021-03-02
CVE-2021-26855 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2023-08-22
CVE-2023-27532 added to CISA KEV
This vulnerability was recognized for active exploitation, further complicating the threat landscape.
Recordedfuture
2026-01-13
CVE-2025-68947 published
A vulnerability affecting multiple systems was disclosed, contributing to the overall increase in exploited CVEs.
Recordedfuture
2026-03-04
CVE-2026-20131 published
A new vulnerability was disclosed, later added to CISA's KEV list for active exploitation.
Recordedfuture
2026-03-06
First public PoC for CVE-2026-20131
Proof-of-concept code was made publicly available, increasing the risk of exploitation.
Technadu
2026-03-19
CVE-2026-20131 added to CISA KEV
CISA confirmed active exploitation of this vulnerability, highlighting its critical nature.
Technadu