A Perfect Storm of Vulnerabilities: How AI-Driven Attacks Are Overwhelming Traditional Patching Models
The cybersecurity landscape has reached a boiling point. According to a recent report from Rapid7, the traditional patching model is no longer effective in keeping pace with the sheer volume and speed of vulnerabilities being disclosed by attackers using artificial intelligence (AI). In the second quarter of 2026, the number of high- and critical-level vulnerabilities (CVSS 7 to 10) more than doubled compared to the same period last year, reaching an astonishing 8,539. Meanwhile, new exploited vulnerabilities increased by a staggering 40%.
This perfect storm is being driven by AI’s ability to rapidly scan for vulnerabilities, create proof-of-concept code, and test exploitability at unprecedented speeds. “AI can do both discovery and exploitation,” explains Christiaan Beek, Rapid7’s Vice President of Cyber Intelligence. However, the key issue lies in the surrounding context: attackers cannot use the exploit if their target is properly defended with multiple firewalls and other security measures.
The introduction of vibe coding has further exacerbated this problem. Vibe coding involves using AI to write new code based on old templates, often containing the same vulnerabilities as before. This means that even if a vulnerability is fixed in one application, it can still be found in another app using the same vibe-coded template. As Beek notes, “I’ve seen research on vibe-coded financial apps that all contained the same vulnerabilities; indicating that AI is using old templates to write new code still containing the old mistakes.”
The traditional patching model is being overwhelmed by the sheer volume of vulnerabilities being disclosed daily. Defenders are struggling to keep up with the pace, as attackers only need one weak spot in their environment to gain access. The report highlights a widening gap between what’s disclosed and what any team can realistically triage. “We’ve become so dependent on multiple types of vendors that the exposure to visibility for our defenders is way more difficult than that for the attacker,” Beek comments.
The report also notes an increase in what Rapid7 terms “Holy Grail” vulnerabilities – those that don’t require credentials or user interaction. These vulnerabilities have shown a 9-point year-over-year increase and account for 25 of the 40 exploited vulnerabilities in Q2 2026. As Beek explains, “We’ve seen a lot of those being released. As an attacker, I can execute close to a device or product without needing any form of authentication – and that’s a serious flaw.”
Nation-state actors from the cybersecurity axis of evil (China, Russia, Iran, and North Korea) are also highlighted in the report. Persistent activity from these groups includes attacks on Ukraine and its supporters by Russia, the US and US allies by Iran, Taiwan by China, and anything they think can be monetized by North Korea.
The bottom line is that defenders need to rethink their approach to patching and vulnerability management. As Beek emphasizes, “It’s not that nation-state APTs are any more advanced than financially motivated criminal gangs – it’s just that motivations and resources are different.” The report serves as a wake-up call for organizations to reassess their security posture and adopt a more proactive, AI-driven approach to detecting and responding to vulnerabilities.
Source: SecurityWeek — 2026-08-18