THE report on vulnerabilities and exploits in Q2 2026 highlights a significant increase in registered vulnerabilities, largely due to the rising use of AI in software development. Key findings include a surge in critical vulnerabilities, with AI tools contributing both to discovery and exploitation. Noteworthy vulnerabilities include CVE-2026-25253 (OpenClaw), CVE-2026-41948 (Dify), CVE-2026-45386 (Open WebUI), and CVE-2026-45501 (Microsoft Exchange).
The exploitation cases indicate a trend where vulnerabilities are being published without waiting for CVE registrations, giving attackers a time advantage. The report advises organizations to adopt real-time monitoring and improve access controls alongside regular patch management.