AI-accelerated vulnerability discovery and exploit development are compressing defenders’ patching windows to the point that traditional monthly and quarterly cycles no longer work, researchers at Rapid7 are warning in new 2026 threat landscape data summarized by SecurityWeek.[1][14]
In what Rapid7 and industry observers describe as a “compression era,” disclosures of high and critical vulnerabilities scored between 7.0 and 10.0 on CVSS nearly doubled year-over-year, with one analysis citing an increase from 4,268 in Q2 2025 to 8,539 in Q2 2026.[1][3] Over the same period, Rapid7’s global report found exploited high and critical vulnerabilities more than doubled, jumping 105% from 71 in 2024 to 146 in 2025 as attackers increasingly operationalized flaws within days of disclosure.[14] SecurityWeek’s coverage notes that newly exploited vulnerabilities tracked in its dataset rose to 40 in Q2 2026, an 8% increase that underscores how quickly attackers are turning fresh bugs into working intrusion paths.[1]
Rapid7’s threat analysis, echoed by independent reporting from TechBytes and SecurityWeek, shows the average “window of defense” between public disclosure and the appearance of automated exploits in the wild shrank from roughly 14 days in 2024 to just 3.2 days in early 2026.[3][6] Researchers describe attackers using large language models tuned for security research to reverse engineer binary patches, identify the underlying flaw, and generate exploit scripts within hours of a vendor update, even in the absence of public proof-of-concept code.[3][6] One case highlighted in a related SecurityWeek feature saw threat actors exploiting a newly listed CVE within about 20 hours of release by weaponizing only the descriptive text, underscoring how AI tooling has erased the buffer defenders once relied on between disclosure and exploitation.[2]
At the same time, remediation capacity inside enterprises is not keeping up with this AI-driven surge, creating a widening gap between the number of serious bugs and the subset that ever gets fixed.[2][8][12] The Cloud Security Alliance’s “AI-Driven Patch Wave” paper cites Qualys benchmarks showing mean time to remediate critical vulnerabilities in complex enterprise applications now stretching to more than five months, even as exploit timelines collapse to days.[12] SecurityWeek’s analysis of industry data, including Verizon’s latest Data Breach Investigations Report, highlights that the median time to fix a known-exploited flaw has risen to well over a month, with only a fraction of discovered vulnerabilities ever fully patched in production environments.[2] That lag has prompted regulators and major platform providers to rethink rigid patch-deadline mandates in favor of more nuanced, risk-based triage models, according to multiple recent commentaries.[2][10]
In response, Rapid7 is arguing that defenders must stop treating CVSS scores as the primary signal and instead prioritize “exposure”—which assets are reachable, exploitable and business-critical—over raw severity numbers.[1][13] The company’s latest exposure management tooling, delivered through its Remediation Hub, is designed to fuse vulnerability data with contextual risk insights so teams can see which unpatched issues are actually likely to be exploited on their own networks and coordinate remediation with IT operations more effectively.[13] SecurityWeek’s coverage of these changes frames them as part of a broader industry pivot away from attempting to patch every high-severity CVE and toward continuously hardening the subset of systems that matter most to attackers.[1][5]
Researchers across Rapid7, the Cloud Security Alliance and other groups now recommend that organizations measure their real patch deployment times, not policy targets, and adopt continuous hardening strategies that bake prioritization, segmentation and exploitability modeling into daily operations.[3][8][12] That means focusing first on actively exploited vulnerabilities on internet-facing systems, tightening controls around exposed business-critical applications, and using AI-driven risk scoring to decide which patches must be fast-tracked versus monitored.[3][8][13] As AI accelerates both vulnerability discovery and exploit development, the emerging consensus from these reports is clear: defenders will not win by trying to outrun the volume of CVEs, but by out-optimizing attackers on which exposures stay reachable in the first place.[1][3][8]
References
- AI-Driven Vulnerability Surge Breaks the Traditional Patching Model
- Is Patching Dead? Vulnerability Management in the Post-Mythos Era
- The Vanishing Window: Rapid7 Decodes the 2026 Threat Landscape
- Toward Better Patching — A New Approach with a Dose of AI
- Cyber Insights 2026: Malware and Cyberattacks in the Age …
- The AI-Driven Patch Wave
- OpenAI Refocuses Cybersecurity Efforts on Patching Over …
- The AI-Driven Patch Wave – Lab Space
- Rapid7 Accelerates Exposure Remediation with AI-Generated Risk …
- Rapid7 2026 Global Threat Landscape Report Shows Exploited …
