Wallarm

59 stats5 reports

All Statistics

In 2025, 36% of AI-related KEVs involved an API attack surface.

AI-related VulnerabilitiesAPI SecurityAI-related KEVsKEVsAPI Attack Surface

In 2025, 17% of 67,058 published vulnerabilities (11,053 vulnerabilities) were API-related.

API SecurityVulnerabilitiesAPI Vulnerabilities

97% of API vulnerabilities can be exploited with a single request.

API SecurityExploitabilityAPI VulnerabilitiesVulnerabilities

In Q3 2025, Model Context Protocol vulnerabilities surged by 270% compared to Q2 2025.

APIVulnerabilities

In Q3 2025, authorization issues made up 28% of all API vulnerabilities.

APIVulnerabilities

In Q3 2025, vulnerabilities related to Agentic AI rose by 67%, indicating early signs of risk in autonomous orchestration.

APIVulnerabilities

Of the 2,869 security issues analysed in Agentic AI projects, the majority were API-related (65%).

AIAgentic AIAPI

25% of reported security issues in Agentic AI remain open.

AIAgentic AIVulnerabilities

60% of top vulnerabilities found in Agentic AIwere access control-related

AIAgentic AIVulnerabilities

More than 50% of all recorded CISA exploited vulnerabilities were API-related for the first time, a 30% increase from the year before.

48% of enterprises report implementing specific security controls for AI deployments.

AISecurity ControlsEnterpriseDeployment Lag

89% of AI-powered APIs relied on insecure authentication mechanisms, like static keys.

AIAPIAuthenticationSecurity

Modern APIs represent over 33% of exploited vulnerabilities in CISA KEV.

Only 11% of AI-powered APIs had robust security measures in place, leaving most endpoints vulnerable.

98.9% of AI vulnerabilities are API related.

AIVulnerabilityAPISecurity

99% of API vulnerabilities are remotely exploitable.

API SecurityRemote ExploitationAPI VulnerabilitiesVulnerabilities

In 2025, 43% of CISA KEV additions were API-related, making APIs the single largest exploited surface in that dataset.

API SecurityAPIsKEV

In 2025, 36% of AI-related vulnerabilities involved APIs (786 of 2,185 AI-related vulnerabilities).

AI-related VulnerabilitiesAPI SecurityAPIs

In 2025, 14% of published AI vulnerabilities were MCP-related (315 MCP-related vulnerabilities).

AI VulnerabilitiesModel Context ProtocolVulnerabilities

MCP vulnerabilities grew 270% from Q2 to Q3 in 2025.

AI SecurityModel Context ProtocolMCP VulnerabilitiesVulnerabilities

59% of API vulnerabilities require no authentication.

API SecurityAuthenticationAPI VulnerabilitiesVulnerabilities

In 2025 breach data, AI platforms and tooling accounted for 15% of API-related breaches, tying software as the largest category in the dataset.

Data BreachesAI PlatformsAPI Security

98% of API vulnerabilities are easy or trivial to exploit.

API SecurityExploitabilityVulnerabilities

In Q3 2025, there were 1,602 disclosed API-related vulnerabilities, representing a 20% increase from Q2 2025.

APIVulnerabilities

In Q3 2025, 16% of vulnerabilities added to CISA's Known Exploited Vulnerabilities catalog were API-related.

APIVulnerabilities

In Q3 2025, Security Misconfiguration accounted for 38% of all API flaws, rising by 33% from Q2 2025.

APIVulnerabilities

In Q3 2025, AI-API vulnerabilities increased by 57%, driven by a 270% rise in Model Context Protocol vulnerabilities.

APIVulnerabilities

Over 700 issues in Agentic AI repositories remain unaddressed.

AIAgentic AIVulnerabilities

Some open security issues in Agentic AI are lingering for 1,200-plus days.

AIAgentic AIVulnerabilities

In 2024, there was an average of three monthly API-related breach incidents—and, at times, as many as five to seven breaches each month.

57% of AI-powered APIs were externally accessible, and 89% relied on insecure authentication mechanisms.

57% of AI-powered APIs were externally accessible.

AIAPIExternal AccessibilitySecurity

Over 50% of exploits in CISA’s Known Exploited Vulnerabilities (KEV) report were API-related in 2024, up from 20% in 2023.

APIVulnerabilityExploitsSecurity

There was an average of three API-related breaches per month in 2024, with some months seeing as many as five to seven.

APIData BreachFrequencyRisk

54% of enterprises report engaging in multiple AI deployments.

AIEnterpriseDeploymentTechnology

35% of enterprises are just beginning their AI journey.

AIEnterpriseDeploymentSecurity readiness

63% of enterprise leaders believe AI increases API security risk.

AIAPISecurity RiskEnterprise Leaders

34% of enterprises admit their security controls are lagging behind AI's rapid deployment.

APIMachine LearningDiscoveryEndpoints

77.4% of API-related vulnerabilities in AI products are directly API-related, such as weak API authentication, inadequate rate limiting, and broken access controls.

WallarmAIAPIVulnerabilityAuthentication

21.5% of AI vulnerabilities are indirectly tied to APIs, including flaws in third-party integrations.

WallarmAIVulnerabilityThird-party IntegrationsAPI

Only 1.1% of the vulnerabilities in AI products were entirely unrelated to APIs.

WallarmAIVulnerabilityNon-APIProduct Vulnerabilities

Attackers can exfiltrate sensitive data in as little as 6 seconds in API attacks.

WallarmAPIData ExfiltrationAttack SpeedRisk

Kernel exploits accounted for 5.4% of the CISA KEV exploits.

WallarmExploitsKernel ExploitsCISA KEVRisk

Supply chain exploits accounted for 1.1% of the CISA KEV exploits.

WallarmExploitsSupply ChainCISA KEVRisk

Wallarm tracked 439 AI-related CVEs in 2024.

AICVEAPIVulnerabilities

Browser exploits accounted for 9.2% of the CISA KEV exploits.

WallarmExploitsBrowser ExploitsCISA KEVRisk

12% of enterprises are waiting for security controls to be ready before deploying AI.

AIEnterpriseDeploymentSecurity Controls

AI vulnerabilities increased by 1,025% from 2023 to 2024.

AIVulnerabilityAPIRisk

Legacy APIs in web applications represent over 18% of exploited vulnerabilities.

18.9% of API-related exploits involved legacy APIs, including AJAX backends and URL parameter-based systems.

APILegacy SystemsExploitsSecurity