Global Threat Intelligence Report:
2026 Mid Year Edition
Data, insights, and key takeaways on the most impactful threats of 2026—from AI and infostealers to ransomware and vulnerabilities.
Vulnerability Intelligence and Patching Management
The data in this section reflects Flashpoint’s comprehensive vulnerability intelligence, covering all attack surfaces—including vendors, endpoints, cloud, Internet of things (IoT), operational technology, open source software (OSS), and third-party libraries and dependencies. Flashpoint’s vulnerability enrichment provides full context into metadata such as EPSS, the MITRE ATT&CK® framework, exploit intelligence, social risk, and ransomware likelihood. The intelligence presented here reflects activity observed from January 1, 2026 to June 30, 2026.
Vulnerability Overview
January 2026 – June 2026
21,667
Vulnerabilities Disclosed
6,808
Pre-NVD Vulnerabilities
4,015
Vulnerabilities with Exploits
What is the Current State of Vulnerabilities and Exploitation?
Flashpoint’s Primary Source Collection (PSC) tracked a rapidly accelerating threat landscape during the first half of 2026, aggregating 21,667 vulnerability disclosures—an 8% increase period-over-period. Of all vulnerabilities collected in H1 2026, Flashpoint found that 19% already possess public or functional exploit code, rendering nearly one in five flaws immediately weaponizable.
While this broad availability provides attackers with an expansive arsenal of potential entry points, their real-world deployment remains highly targeted. To capture this active exploitation, the Flashpoint Known Exploited Vulnerabilities (KEV) catalog tracked 239 flaws undergoing active, in-the-wild exploitation during H1 2026—a 191% increase over the 82 flaws identified by the federal CISA KEV list. The stark contrast between the total number of weaponized exploits and those actually utilized highlights the critical importance of threat-informed prioritization over volume-based patching.
Defenders should triage and patch vulnerabilities as soon as exploit intelligence and remediation data become available. Because reliance on downstream public repositories introduces severe operational delay during this critical window, tracking vulnerabilities at the source is vital. To fill this gap, Flashpoint’s vulnerability research team isolated 6,808 pre-NVD vulnerabilities—accounting for 31% of the total disclosure volume during H1 2026—analyzing and delivering them to users well before they were processed or published by the National Vulnerability Database (NVD). This delta provides organizations with a definitive operational lead-time advantage to harden assets before attackers can capitalize on the broader exploit landscape.
What Are the Defining Vulnerability Trends and Insights in 2026?
AI and CI/CD Pipelines Create Critical New Vulnerability Attack Surfaces
The most critical evolution in H1 2026 is the transition from targeting software code to weaponizing and hijacking underlying AI infrastructure and developer identity ecosystems. Events like the Shai-Hulud Worm fundamentally altered the threat landscape by targeting AI coding assistants directly.
Threat actors are no longer relying on slow, manual exploit configuration; instead, they are increasingly leveraging automated, machine-speed replication frameworks to target development environments and CI/CD pipelines almost instantly upon discovery. We saw the apex of this threat profile with the widespread AntV ecosystem compromise orchestrated by the threat actor group TeamPCP. Utilizing specialized worm frameworks, the threat actors published 637 malicious versions across 323 distinct public packages in a staggering 22-minute window.
As threat actors increasingly target AI, and as models like Mythos may potentially introduce tens of thousands more vulnerabilities into the ecosystem, security teams will need broad, yet detailed vulnerability intelligence that can seamlessly match external exploitability with internal asset discovery to map real-world threat actor utility directly to their exposed perimeter.
Risk Management Shifts from Severity to Threat-Informed Prioritization
While the massive volume of disclosures in the first half of 2026 underscores this crisis, years of historically high vulnerability totals have already made it clear that traditional, severity-based patching models are no longer operationally sustainable. For years, security teams have been forced into reactive cycles, prioritizing “high” (7.0+) or “critical” (9.0+) CVSS ratings with equal urgency.
However, this legacy approach has resulted in unmanageable backlogs; data from Flashpoint’s over 455,000 vulnerability database shows that 35.7% of CVSSv3 and 33% of CVSSv2 ratings fall within high or critical severity brackets, forcing defenders to chase overwhelming volume rather than actual risk. This strain will likely be exacerbated as advanced AI systems threaten to surface thousands of unverified vulnerabilities that security teams will be forced to triage and remediate.
This structural bottleneck is being directly addressed by the issuance of CISA’s Binding Operational Directive (BOD) 26-04. By formalizing threat-informed prioritization on a regulatory level, this directive marks a historic policy shift away from static severity scores. It mandates that federal organizations move past flat CVSS metrics and instead cross-reference security flaws against real-world execution variables, specifically evaluating asset exposure, known exploited status (KEV), technical impact, and exploit automation.
While this risk-based approach promises significant efficiency gains, successfully executing the strategy requires high-fidelity metadata that public sources, such as CVE and NVD, simply do not consistently provide.
The Erosion of Public Vulnerability Enrichment Creates Critical Reliance on KEV
The year 2026 has seen a fundamental and permanent structural shift in Vulnerability Management (VM). Facing an unmanageable surge in CVE disclosure volumes, the National Vulnerability Database (NVD) officially transitioned to a selective enrichment model—stepping away from universally analyzing and scoring every CVE-disclosed vulnerability. For VM teams relying solely on publicly available vulnerability data, this shift introduces severe operational delays, resulting in critical visibility gaps for organizations that use lesser-known or legacy software, especially in niche sectors like medical devices.
With this shift, there is an aggressive industry pivot towards tracking active threat actor utility. With public repositories lagging behind, security teams are turning to the CISA KEV, as it provides confirmation that a given vulnerability is actively being weaponized in the wild. However, despite its usefulness, the CISA KEV is limited in its scope as it only tracks hardware and software used by the federal government and its stakeholders. Flashpoint’s vulnerability intelligence closes this gap, expanding KEV coverage by 335% when compared to CISA’s entire catalogue. With over 7,200 fully enriched KEV entries, security teams are provided comprehensive coverage of known exploited vulnerabilities.
What Are the Key Takeaways for Vulnerability Risk?
1
Massive Severity Inflation Fuels Unmanageable Patching Backlogs
Prioritizing remediation based entirely on static “critical” or “high” CVSS ratings creates unsustainable enterprise workloads. Data from Flashpoint’s database of over 450,000 vulnerabilities shows that on average, 34% of all disclosed flaws (v2 and v3) are designated with a “critical” or “high” rating. Attempting to chase this massive volume forces security teams into reactive, exhausting cycles rather than focusing on actual risk.
2
Machine-Speed Exploitation Erases the Traditional Human Triage Window
With 19% (4,015) of all H1 2026 disclosures dropping with ready-made, functional exploit code at launch, nearly one-in-five flaws are immediately weaponizable. Threat actors are capitalizing on this broad availability by utilizing automated, machine-speed replication frameworks. To keep pace, defenders must leverage immediately available exploit intelligence to isolate perimeters before automation takes over.
3
Public Database Limitations and Delays Leave Niche Sectors Exposed
The NVD’s shift to a selective enrichment model introduces operational delays, leaving organizations using specialized niches, lesser-known, or legacy software blind to critical baseline metrics. Furthermore, while the CISA KEV catalog is helpful, its scope is strictly limited to infrastructure used by the federal government. To claim a true operational lead-time advantage, organizations must rely on intelligence vendors to capture pre-NVD flaws and enrich data with broader global telemetry.
What Are the Best Strategies for Proactive Vulnerability Management?
Implement Exploit-First Prioritization to Neutralize Asset Backlogs
Mandate that vulnerability management workflows prioritize security flaws based on four strict execution variables: remote reachability, public exploit availability, known active exploitation, and exploit automation maturity. By filtering out non-active risks, teams can confidently deprioritize alerts and focus exclusively on the narrow band of flaws actively targeted by adversaries.
Operationalize Pre-NVD Intelligence to Jumpstart Remediation
Shift vulnerability scanning and asset evaluation from a downstream reactive cadence to an upstream, primary-source collection model. Integrate intelligence feeds that provide immediate visibility into pre-NVD discoveries. This operational lead time must be used to deploy proactive mitigations well before public data is finalized or mass automated scanning begins.
Establish Machine-Speed Isolation Playbooks for AI Infrastructure and Supply Chains
Transition from passive monitoring to automated runtime protection across developer environments, identity systems, and CI/CD pipelines. Implement strict, automated behavioral isolation rules that immediately flag or quarantine unauthorized modifications to AI assistant settings or IDE configuration files. By continuously matching external exploitability telemetry with internal asset discovery, security teams can proactively break automated threat loops before they degrade enterprise perimeters.