< Back to all clusters
[TECHNOLOGY] · 12 sources

started · updated

Cybersecurity landscape faces rapid rise in vulnerability exploitation

Cybersecurity reports indicate a rapidly accelerating threat landscape where software vulnerabilities are being exploited faster than organizations can deploy patches. Rapid7’s Q2 2026 report highlights a significant rise in critical vulnerabilities and a surge in publicly available proof-of-concept code, noting that 62% of newly exploited flaws allow for remote, zero-click attacks without authentication.

Specific critical exploits are currently being observed in the wild. A command injection vulnerability in Zimbra Collaboration Suite (CVE-2026-73570) is being actively used to achieve remote code execution via SNMP monitoring components. Similarly, a path traversal flaw in VMware vCenter (CVE-2026-59310) has been linked to a campaign—potentially involving Chinese-speaking actors—that allows attackers to gain root access and deploy ransomware across virtual infrastructure.

In the software development sector, the use of AI-assisted testing is contributing to a massive increase in disclosed CVEs, which researchers suggest is widening the ‘patch gap.’ Additionally, a critical flaw in the popular Node.js library ‘isolated-vm’ was disclosed, allowing for sandbox escapes that could lead to host memory corruption. Experts suggest that traditional ‘patch everything’ strategies are becoming mathematically impossible, necessitating a shift toward exposure management and business-aligned risk prioritization.

Entities

CERT Polska · CISA · Microsoft · Rapid7 · VMware · Zimbra