Skip to main content
LiMP VPN
All news

Kaspersky: Critical Vulnerabilities Up 34% in Q2 2026

Kaspersky: Critical Vulnerabilities Up 34% in Q2 2026

In short: Kaspersky Lab's Q2 2026 security report found 2,700 critical vulnerabilities — a 34% year-on-year increase. Across the first half of 2026 that figure reached 5,200 (up 47%). Researchers uncovered DirtyFrag, a new class of Linux kernel privilege-escalation bugs, while the window between exploit publication and patch availability continues to shrink toward zero.

The Numbers and Why They Matter

On 26 August 2026, Kaspersky Lab published its quarterly vulnerability analysis. The data draws on the company's CVE knowledge base, aggregating records from the National Vulnerability Database (NVD), GitHub Advisory Database, and Russia's federal threat database (BDU FSTEC). The combined dataset is among the most comprehensive public vulnerability tracking sources available.

Q2 2026 headline figures:

  • 2,700 critical vulnerabilities discovered in Q2 — a 34% rise vs Q2 2025.
  • 5,200 critical vulnerabilities in H1 2026 — a 47% rise vs H1 2025.
  • Discovery of a new exploit class, DirtyFrag, targeting Linux kernel memory handling to escalate privileges.

Kaspersky analysts noted that the concern extends beyond raw numbers: researchers uncovered "entire vulnerability classes that had gone undetected for decades," suggesting attackers may have been exploiting them silently for years.

DirtyFrag: What the New Linux Exploit Class Means

DirtyFrag is a new class of Linux kernel vulnerabilities identified in 2026. The attack targets kernel memory management: under specific conditions, an attacker who already has limited system access can escalate privileges to root level.

Why this matters for personal devices: the vast majority of Android smartphones run on the Linux kernel. Privilege escalation is a critical step in multi-stage attacks — typically starting with browser exploitation or a malicious app, then using a kernel flaw to gain full device control. The broader the catalogue of such vulnerabilities, the richer the attacker's toolkit.

For more on mobile threat trends, see the LiMP VPN blog.

The Exploit Race: Why Attack Windows Are Shrinking

Kaspersky documented a growing trend: security researchers increasingly publish working exploit code for vulnerabilities before vendor patches are available. This compresses the patch window — the time between public disclosure and mass exploitation — to near zero in many cases.

AI is accelerating both sides of this dynamic. AI-assisted code analysis helps researchers discover vulnerabilities faster, which partly explains the volume growth. The same tooling is available to attackers, making exploit automation cheaper and more accessible than ever.

According to Kaspersky, one in three cyberattacks on Russian organisations in 2026 started with vulnerability exploitation — not phishing, not password brute-force. This fundamentally shifts the priority of defensive measures.

What This Means for Your Devices

Critical vulnerabilities are potential entry points. Most never directly affect ordinary users — corporate servers and enterprise software are primary targets. But several trends affect personal devices directly:

  • Browsers and mobile operating systems. Hundreds of vulnerabilities are found annually in Chrome, Android, and iOS. Automatic updates are the single most effective protection layer.
  • Public Wi-Fi. Coffee shops, transit hubs, hotels — these are established attack vectors. An attacker on the same network can exploit protocol-level vulnerabilities or intercept unencrypted traffic. A VPN encrypts everything your device sends, making interception worthless — see more on the LiMP VPN features page.
  • Outdated software. Patches release faster than users install them. Devices running unpatched software remain exposed to exploits targeting known vulnerabilities.

Practical Steps to Protect Yourself Now

  • Enable automatic updates on all devices — Android, iOS, Windows, macOS, and apps. The reaction window has tightened: waiting weeks is no longer safe.
  • Use a VPN on public networks. Encrypted traffic is protected against interception via network-level vulnerabilities. LiMP VPN plans start at 69 ₽/month with a verified no-logs policy.
  • Audit old devices. A smartphone that no longer receives security updates is a persistent target. Most manufacturers have dropped Android 12 and below from their patch cycles.
  • Minimise app permissions. Limiting what apps can access reduces the blast radius of any vulnerability exploited inside installed software.
  • Check for your data in breach sets. More critical vulnerabilities in enterprise systems means more exposed user data. Search your email at HaveIBeenPwned.

Sources

Kaspersky: Critical Vulnerabilities Up 34% in Q2 2026