Key Takeaways

  • Forescout Technologies reported a 51% year-over-year increase in published vulnerabilities in the first half of 2026.
  • AI-enabled discovery and exploitation is accelerating attacker activity across IT, OT, IoT, and IoMT environments.
  • Older flaws remain heavily targeted, with 46% of new CISA KEV entries tied to pre-2026 vulnerabilities.

Forescout Technologies has released its 2026 H1 Threat Review Report, detailing a threat landscape reshaped by frontier AI, persistent legacy vulnerabilities, and increasing pressure on critical infrastructure. The report provides quantitative data on expanding digital estates, highlighting a measurable shift toward AI-accelerated vulnerability discovery and specialized device targeting.

Published vulnerabilities jumped 51% year-over-year to 37,137. Vedere Labs notes that more than half of these CVEs were rated high or critical. This steep rise aligns with what independent observers are tracking; for example, the FIRST forecast of roughly 66,000 CVEs for full-year 2026, attributed in part to AI-assisted discovery, highlights broader industry acceleration. In parallel, the research indicates that 46% of additions to CISA’s Known Exploited Vulnerabilities catalog were tied to flaws published before 2026, underscoring the persistent risk from the long tail of unpatched systems inside operational environments.

Ransomware activity also expanded during this period. The report documents a 25% increase in attack claims, reaching 4,544 incidents in the first half of 2026, with 103 active ransomware groups tracked globally. This growth pattern aligns with commentary from multiple analysts. Researchers at Gartner have noted how ransomware groups are diversifying infrastructure, while Forrester analysts point to an expanding affiliate ecosystem that sustains high-volume operations. These external perspectives frame the rise reported in the threat review as a systemic trend.

Threat actors are increasingly pivoting toward exploiting software vulnerabilities for initial access in cloud environments. This aligns with findings from the Google Cloud Threat Horizons H1 2026 report, which indicates that as configuration errors become harder to exploit, software flaws serve as more attractive entry points. This shift signals that cloud-focused defenders must adjust threat models that historically relied primarily on misconfiguration detection.

Geopolitically, the review observed that threat actors associated with China, Russia, and Iran represented 32% of groups with notable activity updates during the period. The report tracks evolving Iranian cyber operations, detailing state-sponsored, criminal, and hacktivist activity targeting operational technology and critical infrastructure. This context parallels public sector analysis from sources like the GAO, which has repeatedly highlighted gaps in infrastructure cyber readiness.

Vedere Labs also tracked more than 5,700 hacktivist attack claims across 98 Telegram channels. While such claims can be inflated, they reveal consistent targeting patterns based on high-visibility geopolitical narratives. The data indicates that AI-enabled tooling is reducing technical barriers for these actors, contributing to a broader democratization of offensive capabilities.

The analysis also highlights software supply chain compromises and sustained targeting of connected devices across OT, IoT, and IoMT environments. Examples include programmable logic controllers, human-machine interfaces, tank gauges, routers, medical devices, and firewalls. Security research from MIT points to similar device-level vulnerabilities, particularly in environments where hardware lifecycles exceed typical patch schedules. This overlap between academic findings and operational threat reports indicates persistent risk accumulation at the device level.

Defensive priorities outlined in the research focus heavily on visibility and segmentation. The organization's chief executive officer emphasized that enterprises often maintain blind spots around unmanaged assets and connected devices, creating initial access opportunities for attackers. This assessment aligns with the NIST Cybersecurity Framework, which mandates risk-based asset visibility and segmentation practices. Although NIST published its CSF 2.0 update in 2024, many enterprises are still operationalizing those recommendations, particularly in OT and healthcare environments.

While segmentation is an established security principle, its operational context has shifted. With threat actors accelerating lateral movement via AI-powered reconnaissance, segmentation functions primarily as an active containment mechanism, slowing attackers to enable detection tools to react. Recognizing this timing challenge, vendors like CrowdStrike and SentinelOne have recently deployed enhancements across endpoint and cloud platforms to process vulnerability signals at higher velocity.

The most frequently targeted industries identified in the study include government, technology, financial services, education, and healthcare. These sectors commonly experience a collision of resource constraints, high-value data, and severe operational pressure. Healthcare organizations, for example, often struggle to maintain continuous patching schedules while managing critical clinical priorities and legacy devices, creating exploitation windows for both commodity ransomware and structured campaigns.

Fundamentally, attack velocity has escalated. AI enables threat actors to execute campaigns faster, while the expanding attack surface of connected devices provides numerous initial access options. Security organizations must manage larger inventories of potential vulnerabilities under sustained pressure from well-resourced adversaries, shifting defensive strategies toward minimizing exposure windows and containing lateral movement.

Forescout’s 2026 H1 Threat Review quantifies a rapidly shifting security landscape. The findings enable security leaders to prioritize structural defenses, confirming that comprehensive asset visibility, network segmentation, and accelerated risk-based remediation are critical operational requirements across traditional IT and specialized OT, IoT, and IoMT environments.