Report by 2026 Global Threat Landscape Report
Rapid7
Key Findings
Exploited high and critical severity vulnerabilities increased 105% from 71 in 2024 to 146 in 2025.
Valid accounts with missing or lax multi-factor authentication (MFA) accounted for 43.9% of all incident response investigations by Rapid7 in 2025, making it the single most common initial access vector.
The median time from a vulnerability's publication to its inclusion in the CISA KEV catalog dropped from 8.5 days to 5.0 days.
Ransomware was involved in 42% of Rapid7 MDR incident response investigations last year.
Total ransomware leak posts increased 46.4% year over year, rising to 8,835 in 2025.
The mean time from a vulnerability's publication to its inclusion in the CISA KEV catalog dropped from 61.0 days to 28.5 days.