Rapid7Intelligence

Adversary research you can operationalize today

CVEs, actor profiles, and detections you can action in Command. From the team that builds Metasploit, Vulnerability & Exploit Database, and Velociraptor.

Emergent Threat6
+0%

Disclosures doubled

High- & critical-severity CVEs year-over-year - 8,539 vs 4,268 in Q2 2025

0%

Holy grail flaws

Of exploited vulnerabilities required no auth and no user interaction (25 of 40)

0

U.S. victims

Ransomware leak-site listings in the U.S. - roughly 9× Germany, the next country

0

Underground listings

Exploit & access listings across 20 dark web sources, 23 CVEs actively traded

quarterly-threat-landscape-report.webp

Quarterly Threat Landscape Report Q2 2026

Ungated research, no sign up required.

Vulnerability and Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Research is only half the loop

Every Intelligence finding feeds the Command Platform, so the CVEs and detections here become prioritisation and hunts you can action.