Radware report: Web DDoS attacks up 110% in H1 2026 as AI aids attackers

Radware's H1 2026 threat report finds web DDoS attacks more than doubled year-on-year, with over 80% of vulnerabilities now exploited before public

Radware report: Web DDoS attacks up 110% in H1 2026 as AI aids attackers

Radware (NASDAQ: RDWR) has published its H1 2026 Global Threat Analysis Report, documenting a broad acceleration in cyberattack volume and sophistication across network and application layers during the first six months of the year. The findings draw on telemetry from the company's cloud and managed security services, as well as its internal threat intelligence team.

Web DDoS attacks grew 110.6% compared with H1 2025 and 36.3% compared with H2 2025. By the end of June, the cumulative volume of web DDoS mitigations had already reached 83% of the total recorded across all of 2025. If current rates hold, Radware's straight-line extrapolation suggests full-year 2026 volumes could be 166% higher than 2025 levels, with North America projected to see the steepest growth at roughly 190%.

At the network layer, Radware recorded an average of 110 DDoS attacks per customer per day during H1 2026, up 36.6% on the 2025 baseline. The company noted a shift in technique: direct-path UDP floods now account for 73% of all mitigated packets, displacing the reflection and amplification methods that previously dominated. The technology sector absorbed 59.4% of all network DDoS attacks, averaging 509 incidents per customer per day.

Vulnerability exploitation enters negative time

The most striking finding in the report concerns the speed of vulnerability exploitation. The mean time from a Common Vulnerabilities and Exposures (CVE) announcement to a first detected attack in the wild has fallen below zero: more than four out of five vulnerabilities tracked by Radware in H1 2026 were actively exploited before their official CVE disclosure. That compares with a mean lag of 21.5 days post-disclosure in 2025 and 53 days in 2024. Exploitation accounted for 62.1% of all web application and API attacks recorded in the period.

Radware attributes part of this acceleration to frontier AI models, which the report says can use semantic reasoning and vulnerability chaining to surface flaws that have evaded years of human review. The company also points to the proliferation of capable open-weight models as a factor lowering the barrier to advanced offensive techniques.

Pascal Geenens, vice president of threat intelligence at Radware, said: "Attackers are increasingly operating at machine speed, launching direct-path DDoS attacks, exploiting vulnerabilities and using agentic AI to automate and speed up their attacks. The growing gap between the speed of attacks and the ability of organisations to detect and respond to them is fundamentally changing the threat landscape."

API visibility gap and market context

A parallel survey embedded in the report highlights a structural exposure in enterprise API estates. Radware found that 77% of organisations are deploying or implementing AI agents, yet only 17.2% report full visibility into those agents' activity. More than 70% of respondents increased internal API usage over the past year, and 81.2% push production API updates at least weekly. Despite that pace, only 6.9% fully document their internal APIs, while 43% document less than 70% of them.

The findings land in a crowded threat-intelligence market where Cloudflare, Akamai, Imperva and Fastly publish competing periodic reports. Vendor-issued threat research serves a dual purpose: it informs defenders and positions the sponsoring company as an authority in segments where it sells protection. Radware's core products compete directly in the web application firewall, DDoS mitigation and API security categories, giving it commercial incentive to emphasise attack volume growth.

Broader regulatory pressure is also relevant here. The EU's NIS2 Directive, which took effect across member states in late 2024, requires operators of essential services to demonstrate incident-detection and response capabilities. DORA imposes comparable obligations on financial-sector entities. Both frameworks increase enterprise appetite for exactly the managed DDoS and API-security services Radware sells, meaning the report's timing ahead of autumn procurement cycles is unlikely to be coincidental.

Radware will host a webinar on 1 October 2026 to discuss the report's findings, led by Geenens. The full report is available via the company's website.