**AI-Driven Vulnerability Surge Overwhelms Traditional Patching Model**
A recent report from Rapid7 has shed light on a disturbing trend in cybersecurity: the sheer volume of vulnerabilities being disclosed is overwhelming traditional patching models. The report, titled “The Compression Era,” highlights how artificial intelligence (AI) is driving this surge, making it increasingly difficult for defenders to keep up.
According to the analysis, the number of high and critical vulnerabilities (CVSS 7 to 10) doubled in Q2 2026 compared to the same period last year. Meanwhile, new exploited vulnerabilities increased by 8% to 40. The difference between the number of vulnerabilities found and those exploited lies in the surrounding context: attackers can’t use a vulnerability if it’s hidden behind multiple firewalls and defensive mechanisms.
But AI is changing this dynamic. By using machine learning algorithms, AI can not only discover new vulnerabilities but also exploit them with ease. This has led to an explosion of “Holy Grail” vulnerabilities, which don’t require credentials or user interaction. These types of vulnerabilities have shown a 9-point year-over-year increase and now account for 25 out of the 40 exploited vulnerabilities in Q2 2026.
Christiaan Beek, Rapid7’s VP of Cyber Intelligence, explains that AI is driving this surge by using old templates to write new code, introducing vulnerabilities into new applications. This creates a never-ending cycle of vulnerability discovery and exploitation.
The problem for defenders is exacerbated by the asymmetry between attack and defense. Attackers only need one weak spot in an organization’s environment, while defenders must defend against multiple types of threats, including endpoints, APIs, and supply chain interactions. Beek notes that this has created a “wider gap between what’s disclosed and what any team can realistically triage.”
The report also highlights persistent nation-state activity from China, Russia, Iran, and North Korea (CRINK). These countries are targeting specific regions and organizations, with motivations driven by espionage, sabotage, or monetization. Ransomware remains a major method of monetization, with the US being the primary target.
So what does this mean for defenders? It’s clear that traditional patching models are no longer effective in the face of an AI-driven vulnerability surge. Defenders must adapt and adopt new strategies to stay ahead of the attackers. This includes:
* Implementing proactive threat hunting and detection capabilities
* Investing in AI-powered security tools to identify and mitigate vulnerabilities
* Continuously monitoring and updating security controls to reflect changing threat landscapes
Ultimately, the rapid evolution of cybersecurity threats demands a more agile and adaptive approach from defenders. By recognizing the limitations of traditional patching models and embracing new technologies and strategies, organizations can better protect themselves against an increasingly sophisticated and relentless threat landscape.
Source: SecurityWeek — 2026-08-18