Disclosures doubled
High- & critical-severity CVEs year-over-year - 8,539 vs 4,268 in Q2 2025
Holy grail flaws
Of exploited vulnerabilities required no auth and no user interaction (25 of 40)
U.S. victims
Ransomware leak-site listings in the U.S. - roughly 9× Germany, the next country
Underground listings
Exploit & access listings across 20 dark web sources, 23 CVEs actively traded
Disclosures doubled
High- & critical-severity CVEs year-over-year - 8,539 vs 4,268 in Q2 2025
Holy grail flaws
Of exploited vulnerabilities required no auth and no user interaction (25 of 40)
U.S. victims
Ransomware leak-site listings in the U.S. - roughly 9× Germany, the next country
Underground listings
Exploit & access listings across 20 dark web sources, 23 CVEs actively traded
Quarterly Threat Landscape Report Q2 2026
Ungated research, no sign up required.
Latest from the Intelligence team
.png?width=3840&quality=75)
Threat Research
SMTP is the key: BPFDoor and AVERAT hitting the network edge

Vulnerabilities and Exploits
Critical Cisco Catalyst SD-WAN Manager API authentication bypass exploited in the wild (CVE-2026-76504)

Vulnerabilities and Exploits
Zero-Day Exploitation of Citrix NetScaler ADC and Gateway: CVE-2026-88771 and CVE-2026-88772

Metasploit
Metasploit Wrap Up: Belgian Waffles, Chocolates, and…Modules-Frites?

Vulnerabilities and Exploits
When Business Email Compromise Starts Rewriting Reality

Podcast
Hacktics & Telemetry, E15: A Brucon Preview

Threat Research
The Fraud Ecosystem: A Transition From Known Marketplaces to a Fragmented Environment

Exposure Management
Patch Tuesday - September 2026
Vulnerability and Exploit Database
Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.
Rapid7 Intelligence, built in
Rapid7 Intelligence powers a suite of open-source tools used by security researchers, pen testers, and threat hunters worldwide. Continuously updated by the community and feeding directly into the Rapid7 Platform.
.png?width=3840&quality=75)
Threat Intelligence Services
Curated, actionable intel that accelerates response across your SOC.
.png?width=3840&quality=75)
Metasploit
The world's most widely used penetration testing framework, helping security teams verify vulnerabilities and manage risk-aware assessments.
.png?width=3840&quality=75)
Velociraptor
An advanced open-source digital forensics and incident response platform for hunting threats across enterprise endpoints at scale.
.png?width=3840&quality=75)
Project Sonar
A security research project that conducts internet-wide surveys to gain insights into global exposure to common vulnerabilities.
Research is only half the loop
Every Intelligence finding feeds the Command Platform, so the CVEs and detections here become prioritisation and hunts you can action.