{"id":4317,"date":"2026-08-26T07:11:40","date_gmt":"2026-08-26T07:11:40","guid":{"rendered":"https:\/\/ribesalat.com\/?p=4317"},"modified":"2026-08-26T07:11:42","modified_gmt":"2026-08-26T07:11:42","slug":"business-cybersecurity-vulnerabilities","status":"publish","type":"post","link":"https:\/\/ribesalat.com\/en\/business-cybersecurity-vulnerabilities\/","title":{"rendered":"A Business Digital Risk Snapshot: Rising Vulnerabilities and Autonomous AI-Powered Attacks"},"content":{"rendered":"<p class=\"wp-block-paragraph\">Cybersecurity vulnerabilities in businesses are no longer a secondary technical indicator. They have become the most reliable barometer of corporate digital risk. The <strong>first half of 2026<\/strong> confirms a trend that no organisation can continue to treat as the sole responsibility of IT: vulnerabilities are increasing in volume, severity and, above all, speed of exploitation. This is compounded by a new phenomenon: <strong>autonomous attacks<\/strong> powered by artificial intelligence, capable of identifying and exploiting a security gap without direct human intervention. This analysis of <strong>business cybersecurity vulnerabilities<\/strong> in 2026 is based on real exploitation data, not projections.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Technical Overview 2025-2026: Greater Volume, Higher Severity and Increasing Pressure<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">The evolution of cybersecurity vulnerabilities in businesses between <strong>2025 and 2026<\/strong> provides a more accurate view of cyber risk than a simple comparison of headline figures. Vulnerabilities are not only becoming more numerous; their technical profile also requires stronger prioritisation and governance capabilities.<\/p>\n<p class=\"wp-block-paragraph\">According to <strong>Tokio Marine HCC<\/strong>\u2019s monthly monitoring, analysed by Rib\u00e9Salat, some months in 2025 recorded higher volumes but a lower average CVSS score due to the proportion of low-severity or informational vulnerabilities. In June 2026, however, the increase was accompanied by elevated severity: <strong>7,964 vulnerabilities<\/strong> and an <strong>average CVSS score of 7.1<\/strong>, driven by a higher number of high-severity flaws in the 7-10 range.<\/p>\n<p class=\"wp-block-paragraph\">The 7.1 score is very close to the 7.2 recorded in November 2025, but with a substantially higher volume. Compared with the 2025 range of 3,036 to 5,519 vulnerabilities per month, the June 2026 figure represents an increase of approximately <strong>44.3%<\/strong> compared with December 2025 and more than double, or <strong>115.2%<\/strong>, the February 2025 figure.<\/p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th><strong>Period<\/strong><\/th>\n<th><strong>Vulnerabilities\/month<\/strong><\/th>\n<th><strong>Average CVSS<\/strong><\/th>\n<th><strong>Assessment<\/strong><\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>February 2025<\/td>\n<td>\u22483,700<\/td>\n<td>Moderate<\/td>\n<td>Lower end of the 2025 volume range<\/td>\n<\/tr>\n<tr>\n<td>September 2025<\/td>\n<td>\u22484,340<\/td>\n<td>Moderate<\/td>\n<td>Higher volume, contained severity<\/td>\n<\/tr>\n<tr>\n<td>November 2025<\/td>\n<td>\u22485,100<\/td>\n<td>7.2<\/td>\n<td>Temporarily high severity<\/td>\n<\/tr>\n<tr>\n<td>December 2025<\/td>\n<td>\u22485,519<\/td>\n<td>Moderate<\/td>\n<td>Upper end of the 2025 range<\/td>\n<\/tr>\n<tr>\n<td>June 2026<\/td>\n<td>7,964<\/td>\n<td>7.1<\/td>\n<td>Peak volume and sustained high severity<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p class=\"wp-block-paragraph\"><em>Source: monthly vulnerability monitoring; Rib\u00e9Salat internal analysis based on Tokio Marine HCC data.<\/em><\/p>\n<p class=\"wp-block-paragraph\">The key is not to count vulnerabilities, but to translate that volume into risk decisions by prioritising actual criticality, internet exposure and potential business impact. At this point, vulnerability management ceases to be a purely technical task and becomes the barometer of maturity in the fight against <strong>business cybersecurity vulnerabilities<\/strong>.<\/p>\n<figure class=\"wp-block-image aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-4324\" src=\"https:\/\/ribesalat.com\/wp-content\/uploads\/2026\/08\/Gemini_Generated_Image_yc9mw4yc9mw4yc9m-1024x682.jpg\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" srcset=\"https:\/\/ribesalat.com\/wp-content\/uploads\/2026\/08\/Gemini_Generated_Image_yc9mw4yc9mw4yc9m-300x200.jpg 300w, https:\/\/ribesalat.com\/wp-content\/uploads\/2026\/08\/Gemini_Generated_Image_yc9mw4yc9mw4yc9m-768x512.jpg 768w, https:\/\/ribesalat.com\/wp-content\/uploads\/2026\/08\/Gemini_Generated_Image_yc9mw4yc9mw4yc9m-1024x682.jpg 1024w, https:\/\/ribesalat.com\/wp-content\/uploads\/2026\/08\/Gemini_Generated_Image_yc9mw4yc9mw4yc9m-1536x1023.jpg 1536w, https:\/\/ribesalat.com\/wp-content\/uploads\/2026\/08\/Gemini_Generated_Image_yc9mw4yc9mw4yc9m-2048x1364.jpg 2048w\" alt=\"\" width=\"1024\" height=\"682\" \/><\/figure>\n<p class=\"wp-block-paragraph\"><em>Explore the full classification in our guide to <a href=\"https:\/\/ribesalat.com\/tipos-de-ciberriesgo-cuales-son-y-como-contrarrestarlos\/\">types of cyber risk and how to mitigate them<\/a>.<\/em><\/p>\n<h2 class=\"wp-block-heading\"><strong>From Vulnerability to Attack: Why Exploiting a Security Gap Is Now a Matter of Minutes<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">One of the most difficult messages to convey to business leaders about cybersecurity vulnerabilities is that many no longer require a sophisticated attack or weeks of preparation. Critical flaws have been observed in <strong>remote support tools, VPNs, browsers, file transfer servers and web applications<\/strong>. When these systems are internet-facing or unpatched, attackers can move from identification to exploitation very quickly by creating a privileged session, executing code or moving laterally to other connected assets.<\/p>\n<p class=\"wp-block-paragraph\">The <strong>Trivy case<\/strong> clearly illustrates this acceleration. In March 2026, a threat actor identified as <strong>TeamPCP<\/strong> compromised Aqua Security\u2019s open-source Trivy scanner and its associated GitHub Actions, rewriting <strong>76 of 77 release tags<\/strong> with credential-stealing malware. The incident, designated CVE-2026-33634 and rated critical with a <strong>CVSS score of 9.4<\/strong>, turned a trusted security tool into an attack vector for thousands of development pipelines. According to Beazley Security, the operation accelerated when <strong>an autonomous AI agent scanned thousands of public repositories, identified weaknesses in access controls and exploited them without direct human intervention<\/strong>.<\/p>\n<p class=\"wp-block-paragraph\">The assumption that smaller organisations are not targets is no longer valid. Many attacks begin through automated scanning for vulnerable versions, exposed management panels or reused credentials. Attackers then decide whether to monetise access through ransomware, data theft or fraud. Not every vulnerability results in an incident, but some drastically shorten the distance between <strong>being exposed<\/strong> and <strong>being compromised<\/strong>.<\/p>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><em>\u201cAt Rib\u00e9Salat, we see that many companies have advanced very quickly in their digital transformation, but have not always reviewed their actual exposure, security controls or the suitability of their cyber programme with the same level of depth and on a sufficiently regular and up-to-date basis,\u201d<\/em> explains <strong>Montserrat Recio<\/strong>, Senior Cybersecurity Specialist at Rib\u00e9Salat.<\/p>\n<\/blockquote>\n<h2 class=\"wp-block-heading\"><strong>The AI Multiplier Effect: From Traditional Automation to Autonomous Attacks<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">The difference between traditional cybercrime automation and autonomous AI-powered attacks is not speed, <strong>it is autonomy<\/strong>. Conventional automation follows fixed rules and requires an operator to make each decision. AI agents, by contrast, set objectives, create their own workflows, learn and change strategy in real time, at near-zero marginal cost.<\/p>\n<p class=\"wp-block-paragraph\">According to Beazley Security\u2019s first-quarter 2026 report, exploited vulnerabilities increased by <strong>43%<\/strong> quarter on quarter, with more than <strong>15,200 newly disclosed vulnerabilities<\/strong>, almost 3,900 of which were high-risk, and a 43% increase in additions to CISA\u2019s Known Exploited Vulnerabilities (<strong>KEV<\/strong>) Catalogue. The multiplier effect can be illustrated simply: whereas an attacker might previously have launched 10 campaigns and compromised 100 victims, an operator with ten AI agents can now launch <strong>100 campaigns against 10,000 targets<\/strong>.<\/p>\n<p class=\"wp-block-paragraph\">This phenomenon partly explains the increase in cybersecurity vulnerabilities during the first half of the year. NIST acknowledges that the National Vulnerability Database can no longer enrich every record at the rate at which vulnerabilities are being discovered. Tools such as Google\u2019s <strong>Big Sleep<\/strong> agent, which identified a vulnerability in SQLite before it was exploited, and coordinated disclosure programmes such as <strong>Anthropic\u2019s<\/strong> are accelerating the discovery of flaws in open-source code. Organisations have more CVEs to manage, while the window for patching them before exploitation by a human or autonomous agent has narrowed to <strong>hours<\/strong>.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Critical Vulnerabilities in the First Half of the Year: What Businesses Should Monitor<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">The most significant <strong>business cybersecurity vulnerabilities<\/strong> identified during the first half of the year share a common pattern: they affect widely deployed technologies, including cloud environments, VPNs, firewalls, browsers, collaboration tools and enterprise management systems, and can often be exploited remotely without prior credentials. This intensifies digital supply chain risk, or third-party cyber risk. Businesses must protect not only the systems they directly control, but also understand what is happening across their technology ecosystem, including cloud providers, SaaS platforms, integrations and remote access tools.<\/p>\n<p class=\"wp-block-paragraph\">A critical vulnerability affecting a single vendor can impact <strong>thousands of organisations<\/strong> simultaneously. A flaw in a booking platform or cloud provider can lead to operational disruption, fraud, regulatory penalties or reputational harm, even where the affected business has made no direct error. As highlighted by <a href=\"https:\/\/ribesalat.com\/consultoria-de-riesgo\/\">Rib\u00e9Salat risk consulting<\/a>, managing vulnerabilities means managing business risk: applying patches is not enough. Organisations must know which assets are critical and understand the impact that an interruption could have.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Sector Impact: IT\/OT Convergence and the Hospitality Industry<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">Although cybersecurity vulnerabilities affect every sector, their impact is not the same for all organisations. The convergence of information technology (IT) and operational technology (OT) is particularly concerning in industry: a vulnerability may lead not only to a data breach, but also to the shutdown of a production line. Manufacturing, automotive, engineering, logistics and energy companies should prioritise reviews of exposed assets and business continuity arrangements for incidents such as ransomware.<\/p>\n<p class=\"wp-block-paragraph\">The <strong>hospitality industry<\/strong> is another environment with significant cyber exposure. It handles large volumes of personal and financial data and depends on booking, payment, guest Wi-Fi and property management systems, including <strong>PMS, CRS and point-of-sale systems<\/strong>, that operate continuously. The most common cyber losses in the sector include:<\/p>\n<ul class=\"wp-block-list\">\n<li>Ransomware affecting hotel management systems.<\/li>\n<li>Theft of guests\u2019 personal and financial data.<\/li>\n<li>Email fraud designed to divert payments.<\/li>\n<li>Attacks on booking platforms or technology providers.<\/li>\n<li>Operational disruption caused by system unavailability.<\/li>\n<li>Risks associated with public or poorly segmented Wi-Fi networks.<\/li>\n<\/ul>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><em>\u201cIn sectors such as hospitality, cybersecurity has a clear reputational dimension: customer trust depends on how the company protects personal data and ensures service continuity,\u201d<\/em> notes <strong>Montserrat Recio<\/strong>.<\/p>\n<\/blockquote>\n<p class=\"wp-block-paragraph\"><em>The <a href=\"https:\/\/www.incibe.es\/empresas\/guias\/ciberseguridad-el-sector-turismo-y-ocio-guia-recomendaciones-empresas\" target=\"_blank\" rel=\"noopener\">INCIBE and SEGITTUR guide for the tourism and leisure sector<\/a> recommends verifying suspicious emails through alternative channels, implementing multi-factor authentication and separating guest Wi-Fi from the internal network.<\/em><\/p>\n<h2 class=\"wp-block-heading\"><strong>From Risk Assessment to Resilience<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">Greater volume, faster exploitation and more autonomous attacks: <strong>business cybersecurity vulnerabilities<\/strong> are growing at the same pace as digital transformation. Understanding the data is the first step; taking action is the next. In the second article in this series, <em>From Risk to Resilience: Governance, People and Cyber Insurance in the Face of AI-Powered Threats<\/em>, we explain how to turn this exposure into an effective strategy for governance, culture and risk transfer.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cybersecurity vulnerabilities in businesses are no longer a secondary technical indicator. They have become the most reliable barometer of corporate digital risk. The first half of 2026 confirms a trend that no organisation can continue to treat as the sole responsibility of IT: vulnerabilities are increasing in volume, severity and, above all, speed of exploitation. [&hellip;]<\/p>\n","protected":false},"author":15,"featured_media":4320,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[29,31,37,36],"tags":[],"class_list":["post-4317","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-gestion-de-riesgos","category-innovacion-y-tecnologia","category-innovation-and-technology","category-risk-management"],"_links":{"self":[{"href":"https:\/\/ribesalat.com\/en\/wp-json\/wp\/v2\/posts\/4317","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ribesalat.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ribesalat.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ribesalat.com\/en\/wp-json\/wp\/v2\/users\/15"}],"replies":[{"embeddable":true,"href":"https:\/\/ribesalat.com\/en\/wp-json\/wp\/v2\/comments?post=4317"}],"version-history":[{"count":5,"href":"https:\/\/ribesalat.com\/en\/wp-json\/wp\/v2\/posts\/4317\/revisions"}],"predecessor-version":[{"id":4330,"href":"https:\/\/ribesalat.com\/en\/wp-json\/wp\/v2\/posts\/4317\/revisions\/4330"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ribesalat.com\/en\/wp-json\/wp\/v2\/media\/4320"}],"wp:attachment":[{"href":"https:\/\/ribesalat.com\/en\/wp-json\/wp\/v2\/media?parent=4317"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ribesalat.com\/en\/wp-json\/wp\/v2\/categories?post=4317"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ribesalat.com\/en\/wp-json\/wp\/v2\/tags?post=4317"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}