Security Bearish 7

Rapid7 Report: Exploited Software Flaws More Than Doubled in 2025

Rapid7's latest vulnerability research reveals a dramatic surge in the exploitation of high and critical software flaws, with the volume more than doubling over the past year. The report highlights a dangerous compression of the 'disclosure-to-attack' window, leaving organizations with significantly less time to secure their infrastructure.

· 3 min read ·
Share

Key Takeaways

  • Rapid7's latest vulnerability research reveals a dramatic surge in the exploitation of high and critical software flaws, with the volume more than doubling over the past year.
  • The report highlights a dangerous compression of the 'disclosure-to-attack' window, leaving organizations with significantly less time to secure their infrastructure.

Mentioned

Rapid7 company RPD

Key Intelligence

Key Facts

  1. 1Exploited high and critical software flaws more than doubled in 2025 compared to 2024.
  2. 2The 'disclosure-to-attack' window has significantly compressed, often shrinking to less than 24 hours.
  3. 3Attackers are increasingly using automated scanning to identify targets immediately after CVE disclosure.
  4. 4Edge technologies and management appliances remain primary targets for high-impact exploitation.
  5. 5Rapid7's research highlights a shift toward more efficient, volume-driven attack strategies by threat actors.
  6. 6The surge in exploitation necessitates a move from reactive patching to risk-based exposure management.
Cybersecurity Threat Level

Analysis

The cybersecurity landscape underwent a significant shift in 2025 as the volume of exploited high and critical software vulnerabilities more than doubled compared to previous years. According to the latest research from Rapid7, this surge is not merely a quantitative increase but represents a qualitative change in how threat actors operate. The primary driver behind this trend is the rapid compression of the 'disclosure-to-attack' window—the time between a vulnerability being publicly announced and the first recorded instance of its exploitation in the wild. This development marks a critical turning point for SaaS and Cloud providers, who must now defend against automated, near-instantaneous exploitation cycles.

Historically, security teams could rely on a grace period of several days or even weeks to test and deploy patches. However, Rapid7's data suggests that this window has effectively vanished for many high-profile vulnerabilities. Attackers are increasingly leveraging sophisticated scanning tools and AI-driven automation to identify vulnerable systems within hours of a CVE (Common Vulnerabilities and Exposures) disclosure. For cloud-native organizations, this means that the traditional reactive patching model is no longer sufficient. The scale and interconnectedness of cloud environments amplify the risk, as a single unpatched edge device or management interface can serve as an entry point for lateral movement across an entire enterprise network.

According to the latest research from Rapid7, this surge is not merely a quantitative increase but represents a qualitative change in how threat actors operate.

This trend is further exacerbated by the rising prevalence of zero-day exploits and the targeting of 'edge' technologies—such as VPNs, firewalls, and file-transfer appliances—which often sit outside the standard automated update cycles of core operating systems. Rapid7's findings indicate that threat actors are prioritizing these high-impact targets because they offer a direct path to sensitive data and internal infrastructure. The doubling of exploited flaws suggests that the barrier to entry for sophisticated attacks is lowering, as exploit kits and proof-of-concept code are distributed more quickly through underground forums and even public repositories.

What to Watch

For CISOs and IT leadership, the implications are clear: the focus must shift from comprehensive patching to risk-based exposure management. With the volume of vulnerabilities doubling, it is mathematically impossible for most teams to patch everything at the speed required by the current threat environment. Organizations must prioritize vulnerabilities based on their exploitability and the criticality of the affected assets. This requires a deeper integration of threat intelligence into the vulnerability management lifecycle, allowing teams to identify which flaws are actually being weaponized in the wild versus those that are merely theoretical risks.

Looking ahead to 2026, the industry should expect this trend to accelerate. As attackers continue to refine their automation capabilities, the 'time to exploit' will likely reach a point of near-concurrency with disclosure. This will necessitate a broader adoption of 'secure-by-design' principles and the implementation of automated mitigation strategies, such as virtual patching and micro-segmentation, to buy time for permanent fixes. The Rapid7 report serves as a stark warning that the window for defense is closing, and the speed of response has become the most critical metric in modern cybersecurity.

Cite This Page

"Rapid7 Report: Exploited Software Flaws More Than Doubled in 2025." SaaS Intelligence Brief, March 19, 2026. https://getsaasbrief.com/story/rapid7-exploited-vulnerabilities-surge-2025

How we covered this story

Every story in our saas coverage is assembled from multiple primary sources, cross-referenced for factual consistency, and scored along three independent dimensions: sentiment, operational impact, and source-cluster confidence. Single-source rumors and unverifiable claims do not pass our editorial gate. When a story shows "Verified by N sources" with N≥2, the development is independently corroborated; when N=1, we mark it explicitly so readers can weigh the signal accordingly.

Impact scoring uses a 1-10 scale weighted toward regulatory, financial, and operational consequence rather than coverage volume. A topic that runs in every outlet but moves no real decisions ranks lower than a niche regulatory filing that reshapes how operators in the saas space have to behave. Read our full methodology for the scoring rubric, our glossary for term definitions, and our trends index for the longitudinal view across the beat.

Sources are only linked to a story once they clear our classification pipeline at a minimum 35 percent relevance threshold. According to that methodology, reviewed July 2026, this follows multi-source corroboration standards recommended by journalism research bodies such as the Reuters Institute for the Study of Journalism.

See something wrong in this story — a wrong fact, a broken source link, a misattributed entity? Report a data issue.