99% of API vulnerabilities are remotely exploitable.
WallarmAPI ThreatStats Report 2026·Feb 17, 2026
API SecurityRemote ExploitationAPI VulnerabilitiesVulnerabilities
In 2025, 17% of 67,058 published vulnerabilities (11,053 vulnerabilities) were API-related.
WallarmAPI ThreatStats Report 2026·Feb 17, 2026
API SecurityVulnerabilitiesAPI Vulnerabilities
In 2025, 43% of CISA KEV additions were API-related, making APIs the single largest exploited surface in that dataset.
WallarmAPI ThreatStats Report 2026·Feb 17, 2026
API SecurityAPIsKEV
In 2025, 36% of AI-related vulnerabilities involved APIs (786 of 2,185 AI-related vulnerabilities).
WallarmAPI ThreatStats Report 2026·Feb 17, 2026
AI-related VulnerabilitiesAPI SecurityAPIs
In 2025, 14% of published AI vulnerabilities were MCP-related (315 MCP-related vulnerabilities).
WallarmAPI ThreatStats Report 2026·Feb 17, 2026
AI VulnerabilitiesModel Context ProtocolVulnerabilities
97% of API vulnerabilities can be exploited with a single request.
WallarmAPI ThreatStats Report 2026·Feb 17, 2026
API SecurityExploitabilityAPI VulnerabilitiesVulnerabilities
MCP vulnerabilities grew 270% from Q2 to Q3 in 2025.
WallarmAPI ThreatStats Report 2026·Feb 17, 2026
AI SecurityModel Context ProtocolMCP VulnerabilitiesVulnerabilities
98% of API vulnerabilities are easy or trivial to exploit.
WallarmAPI ThreatStats Report 2026·Feb 17, 2026
API SecurityExploitabilityVulnerabilities
59% of API vulnerabilities require no authentication.
WallarmAPI ThreatStats Report 2026·Feb 17, 2026
API SecurityAuthenticationAPI VulnerabilitiesVulnerabilities
In 2025 breach data, AI platforms and tooling accounted for 15% of API-related breaches, tying software as the largest category in the dataset.
WallarmAPI ThreatStats Report 2026·Feb 17, 2026
Data BreachesAI PlatformsAPI Security
In Q3 2025, vulnerabilities related to Agentic AI rose by 67%, indicating early signs of risk in autonomous orchestration.
WallarmWallarm Releases Q3 2025 API ThreatStats Report: API Vulnerabilities Up 20%, MCP Risks Surge 270%.html·Oct 30, 2025
APIVulnerabilities
In Q3 2025, authorization issues made up 28% of all API vulnerabilities.
WallarmWallarm Releases Q3 2025 API ThreatStats Report: API Vulnerabilities Up 20%, MCP Risks Surge 270%.html·Oct 30, 2025
APIVulnerabilities
In Q3 2025, Model Context Protocol vulnerabilities surged by 270% compared to Q2 2025.
WallarmWallarm Releases Q3 2025 API ThreatStats Report: API Vulnerabilities Up 20%, MCP Risks Surge 270%.html·Oct 30, 2025
APIVulnerabilities
In Q3 2025, there were 1,602 disclosed API-related vulnerabilities, representing a 20% increase from Q2 2025.
WallarmWallarm Releases Q3 2025 API ThreatStats Report: API Vulnerabilities Up 20%, MCP Risks Surge 270%.html·Oct 30, 2025
APIVulnerabilities
In Q3 2025, 16% of vulnerabilities added to CISA's Known Exploited Vulnerabilities catalog were API-related.
WallarmWallarm Releases Q3 2025 API ThreatStats Report: API Vulnerabilities Up 20%, MCP Risks Surge 270%.html·Oct 30, 2025
APIVulnerabilities
In Q3 2025, Security Misconfiguration accounted for 38% of all API flaws, rising by 33% from Q2 2025.
WallarmWallarm Releases Q3 2025 API ThreatStats Report: API Vulnerabilities Up 20%, MCP Risks Surge 270%.html·Oct 30, 2025
APIVulnerabilities
In Q3 2025, AI-API vulnerabilities increased by 57%, driven by a 270% rise in Model Context Protocol vulnerabilities.
WallarmWallarm Releases Q3 2025 API ThreatStats Report: API Vulnerabilities Up 20%, MCP Risks Surge 270%.html·Oct 30, 2025
APIVulnerabilities
Of the 2,869 security issues analysed in Agentic AI projects, the majority were API-related (65%).
WallarmThe Rise of Agentic AI API ThreatsStats Report Q1 2025·Apr 24, 2025
AIAgentic AIAPI
25% of reported security issues in Agentic AI remain open.
WallarmThe Rise of Agentic AI API ThreatsStats Report Q1 2025·Apr 24, 2025
AIAgentic AIVulnerabilities
60% of top vulnerabilities found in Agentic AIwere access control-related
WallarmThe Rise of Agentic AI API ThreatsStats Report Q1 2025·Apr 24, 2025
AIAgentic AIVulnerabilities
Some open security issues in Agentic AI are lingering for 1,200-plus days.
WallarmThe Rise of Agentic AI API ThreatsStats Report Q1 2025·Apr 24, 2025
AIAgentic AIVulnerabilities
Over 700 issues in Agentic AI repositories remain unaddressed.
WallarmThe Rise of Agentic AI API ThreatsStats Report Q1 2025·Apr 24, 2025
AIAgentic AIVulnerabilities
API-related data breaches tripled in 2024.
Wallarm2025 API ThreatStats Report·Jan 1, 2025
APIData BreachSecurityRisk
There was an average of three API-related breaches per month in 2024, with some months seeing as many as five to seven.
Wallarm2025 API ThreatStats Report·Jan 1, 2025
APIData BreachFrequencyRisk
In 2024, there was an average of three monthly API-related breach incidents—and, at times, as many as five to seven breaches each month.
WallarmAI Security Is API Security·Jan 1, 2025
Machine learning-based discovery tools often identify 31% more API endpoints than those reported by enterprises.
Wallarm2025 API ThreatStats Report·Jan 1, 2025
AIAPIVulnerabilityAuthentication
18.9% of API-related exploits involved legacy APIs, including AJAX backends and URL parameter-based systems.
Wallarm2025 API ThreatStats Report·Jan 1, 2025
APILegacy SystemsExploitsSecurity
Only 11% of AI-powered APIs implemented robust security measures, such as bearer tokens with expiration times.
Wallarm2025 API ThreatStats Report·Jan 1, 2025
AIAPIAuthenticationSecurity
Wallarm's researchers tracked 439 AI-related CVEs, a 1,025% increase from the prior year. Nearly all (99%) were directly tied to APIs.
WallarmAI Security Is API Security·Jan 1, 2025
Newly published API endpoints are discovered by attackers in a mere 29 seconds.
Wallarm2025 API ThreatStats Report·Jan 1, 2025
WallarmAPIEndpointAttack DetectionSpeed
Traditional API security systems can take 5-10 minutes to detect and remediate threats.
Wallarm2025 API ThreatStats Report·Jan 1, 2025
WallarmAPI SecurityThreat DetectionRemediation SpeedTraditional Systems
Wallarm tracked 439 AI-related CVEs in 2024.
Wallarm2025 API ThreatStats Report·Jan 1, 2025
AICVEAPIVulnerabilities
33.5% of the API-related exploits targeted modern APIs, like RESTful and GraphQL.
Wallarm2025 API ThreatStats Report·Jan 1, 2025
APIExploitRESTfulGraphQL
21.5% of AI vulnerabilities are indirectly tied to APIs, including flaws in third-party integrations.
Wallarm2025 API ThreatStats Report·Jan 1, 2025
WallarmAIVulnerabilityThird-party IntegrationsAPI
Kernel exploits accounted for 5.4% of the CISA KEV exploits.
Wallarm2025 API ThreatStats Report·Jan 1, 2025
WallarmExploitsKernel ExploitsCISA KEVRisk
Mobile exploits accounted for 5.9% of the CISA KEV exploits.
Wallarm2025 API ThreatStats Report·Jan 1, 2025
WallarmExploitsMobile ExploitsCISA KEVRisk
Legacy APIs in web applications represent over 18% of exploited vulnerabilities.
WallarmAI Security Is API Security·Jan 1, 2025
AI vulnerabilities increased by 1,025% from 2023 to 2024.
Wallarm2025 API ThreatStats Report·Jan 1, 2025
AIVulnerabilityAPIRisk
Over 50% of exploits in CISA’s Known Exploited Vulnerabilities (KEV) report were API-related in 2024, up from 20% in 2023.
Wallarm2025 API ThreatStats Report·Jan 1, 2025
APIVulnerabilityExploitsSecurity
35% of enterprises are just beginning their AI journey.
Wallarm2025 API ThreatStats Report·Jan 1, 2025
AIEnterpriseDeploymentSecurity readiness
63% of enterprise leaders believe AI increases API security risk.
Wallarm2025 API ThreatStats Report·Jan 1, 2025
AIAPISecurity RiskEnterprise Leaders
77.4% of API-related vulnerabilities in AI products are directly API-related, such as weak API authentication, inadequate rate limiting, and broken access controls.
Wallarm2025 API ThreatStats Report·Jan 1, 2025
WallarmAIAPIVulnerabilityAuthentication
Attackers can exfiltrate sensitive data in as little as 6 seconds in API attacks.
Wallarm2025 API ThreatStats Report·Jan 1, 2025
WallarmAPIData ExfiltrationAttack SpeedRisk
Only 1.1% of the vulnerabilities in AI products were entirely unrelated to APIs.