Security Negative 7

Rapid7 Report: Exploited Software Flaws More Than Doubled in 2025

A new report from Rapid7 reveals that the number of high and critical software vulnerabilities being actively exploited surged by over 100% in 2025. This trend is driven by threat actors significantly compressing the time between a flaw's public disclosure and the launch of active attacks.

· 3 min read · Verified by 4 sources ·

Beat this week

Last 7 days · Security

13 stories
5.4 avg impact
8% positive
8% negative
vs prior 7 days +2 +2 stories vs prior 7 days

Impact 5.4/10, unchanged. Counts are stories in our record, not a market forecast.

Open the change report

Coverage balance Balanced directional read. Positive and negative coverage are within 0 percentage points.

  • 8% positive
  • 85% neutral
  • 8% negative

This story sits in Security — the counts compare this beat's last 7 days with the previous 7 in our verified record, not a market forecast.

Figures are computed live from our source-verified story record (as of ) The volume change compares this window with the prior 7 days in the same record. — see our methodology for how impact and sentiment are derived.

Cybersecurity briefing

Key takeaways

7 impact
Negativesentiment
4sources
3min read
  1. A new report from Rapid7 reveals that the number of high and critical software vulnerabilities being actively exploited surged by over 100% in 2025.
  2. This trend is driven by threat actors significantly compressing the time between a flaw's public disclosure and the launch of active attacks.
Drawn from
  • It Brief New Zealand
  • It Brief Asia
  • It Brief India
  • It Brief Australia

In this briefing

Mentioned

Key Intelligence

Key Facts

  1. 1Exploited high and critical software flaws increased by over 100% in 2025.
  2. 2The disclosure-to-attack window has significantly compressed, often to less than 24 hours.
  3. 3Attackers are prioritizing high-severity flaws that offer administrative access or data exfiltration.
  4. 4Edge devices and third-party software remain the most targeted vectors for initial access.
  5. 5Rapid7's report emphasizes the shift from zero-day hunting to rapid N-day exploitation.
Global Security Posture

Who's Affected

Rapid7
companyPositive
Enterprise IT Teams
companyNegative
Edge Device Vendors
technologyNegative

Analysis

The cybersecurity landscape underwent a seismic shift in 2025 as the volume of exploited high and critical software vulnerabilities more than doubled compared to the previous year. According to the latest research from Rapid7, this surge is not just a statistical anomaly but a reflection of a fundamental change in how threat actors operate. The primary driver behind this escalation is the dramatic compression of the disclosure-to-attack window—the period between a vulnerability becoming public knowledge and its active exploitation in the wild.

In previous years, organizations often had a grace period of days or even weeks to test and deploy patches. However, the 2025 data suggests that this window has effectively collapsed. Attackers are now leveraging automated scanning and AI-assisted exploit development to weaponize new vulnerabilities within hours of their announcement. This N-day exploitation cycle has become so efficient that it often outpaces the internal change management processes of even the most sophisticated enterprises. The report highlights that high and critical flaws are being prioritized by attackers because they offer the path of least resistance to sensitive data and administrative control.

According to the latest research from Rapid7, this surge is not just a statistical anomaly but a reflection of a fundamental change in how threat actors operate.

The industry context for this trend is particularly concerning. As organizations increasingly rely on a complex web of cloud services, edge devices, and third-party software, the attack surface has expanded beyond the traditional perimeter. Rapid7’s findings indicate that edge technologies—such as VPNs, firewalls, and load balancers—have become primary targets. These devices often sit outside the standard visibility of endpoint detection tools, making them ideal entry points for initial access. The doubling of exploited flaws suggests that attackers are no longer just looking for zero-days but are finding immense success in the rapid exploitation of known, high-impact vulnerabilities that remain unpatched.

What to Watch

For cybersecurity leaders, the implications are clear: the traditional Patch Tuesday model is increasingly obsolete. The sheer volume of critical flaws requiring immediate attention is leading to widespread patch fatigue among IT and security teams. This creates a dangerous gap where organizations must choose between the risk of system instability from rapid patching and the risk of catastrophic breach from delayed action. The market impact of this trend is already visible in the increased demand for exposure management and automated remediation technologies. Companies like Rapid7, Tenable, and Qualys are pivoting their platforms to provide more than just vulnerability scanning; they are now focused on vulnerability intelligence that helps teams prioritize which flaws are most likely to be exploited in their specific environment.

Looking ahead, the trend of compressed attack windows is expected to accelerate. As generative AI tools become more integrated into the toolkits of both state-sponsored actors and cybercriminal syndicates, the time to exploit will likely shrink even further. Experts suggest that the next frontier in defense will be autonomous patching and the use of AI-driven defensive agents that can apply temporary mitigations or virtual patches at the network level before a permanent software fix can be deployed. The 2025 data from Rapid7 serves as a stark warning that the speed of defense must now match the speed of the adversary to prevent a total breakdown in digital trust.

Source cluster

Primary reporting

4articles

Cite This Page

"Rapid7 Report: Exploited Software Flaws More Than Doubled in 2025." Cyber Intelligence Brief, March 19, 2026. https://getcyberbrief.com/story/rapid7-warns-exploited-software-flaws-doubled

How we covered this story

Every story in our cybersecurity coverage is assembled from multiple primary sources, cross-referenced for factual consistency, and scored along three independent dimensions: sentiment, operational impact, and source-cluster confidence. Single-source rumors and unverifiable claims do not pass our editorial gate. When a story shows "Verified by N sources" with N≥2, the development is independently corroborated; when N=1, we mark it explicitly so readers can weigh the signal accordingly.

Impact scoring uses a 1-10 scale weighted toward regulatory, financial, and operational consequence rather than coverage volume. A topic that runs in every outlet but moves no real decisions ranks lower than a niche regulatory filing that reshapes how operators in the cybersecurity space have to behave. Read our full methodology for the scoring rubric, our glossary for term definitions, and our trends index for the longitudinal view across the beat.

Sources are only linked to a story once they clear our classification pipeline at a minimum 35 percent relevance threshold. According to that methodology, reviewed July 2026, this follows multi-source corroboration standards recommended by journalism research bodies such as the Reuters Institute for the Study of Journalism.

See something wrong in this story — a wrong fact, a broken source link, a misattributed entity? Report a data issue.