Wallarm

59 STATS5 REPORTS

All Statistics

In 2025, 36% of AI-related KEVs involved an API attack surface.

WallarmAPI ThreatStats Report 2026·Feb 17, 2026
AI-related VulnerabilitiesAPI SecurityAI-related KEVsKEVsAPI Attack Surface

99% of API vulnerabilities are remotely exploitable.

WallarmAPI ThreatStats Report 2026·Feb 17, 2026
API SecurityRemote ExploitationAPI VulnerabilitiesVulnerabilities

In 2025, 17% of 67,058 published vulnerabilities (11,053 vulnerabilities) were API-related.

WallarmAPI ThreatStats Report 2026·Feb 17, 2026
API SecurityVulnerabilitiesAPI Vulnerabilities

In 2025, 43% of CISA KEV additions were API-related, making APIs the single largest exploited surface in that dataset.

WallarmAPI ThreatStats Report 2026·Feb 17, 2026
API SecurityAPIsKEV

In 2025, 36% of AI-related vulnerabilities involved APIs (786 of 2,185 AI-related vulnerabilities).

WallarmAPI ThreatStats Report 2026·Feb 17, 2026
AI-related VulnerabilitiesAPI SecurityAPIs

In 2025, 14% of published AI vulnerabilities were MCP-related (315 MCP-related vulnerabilities).

WallarmAPI ThreatStats Report 2026·Feb 17, 2026
AI VulnerabilitiesModel Context ProtocolVulnerabilities

97% of API vulnerabilities can be exploited with a single request.

WallarmAPI ThreatStats Report 2026·Feb 17, 2026
API SecurityExploitabilityAPI VulnerabilitiesVulnerabilities

MCP vulnerabilities grew 270% from Q2 to Q3 in 2025.

WallarmAPI ThreatStats Report 2026·Feb 17, 2026
AI SecurityModel Context ProtocolMCP VulnerabilitiesVulnerabilities

98% of API vulnerabilities are easy or trivial to exploit.

WallarmAPI ThreatStats Report 2026·Feb 17, 2026
API SecurityExploitabilityVulnerabilities

59% of API vulnerabilities require no authentication.

WallarmAPI ThreatStats Report 2026·Feb 17, 2026
API SecurityAuthenticationAPI VulnerabilitiesVulnerabilities

In 2025 breach data, AI platforms and tooling accounted for 15% of API-related breaches, tying software as the largest category in the dataset.

WallarmAPI ThreatStats Report 2026·Feb 17, 2026
Data BreachesAI PlatformsAPI Security

In Q3 2025, vulnerabilities related to Agentic AI rose by 67%, indicating early signs of risk in autonomous orchestration.

WallarmWallarm Releases Q3 2025 API ThreatStats Report: API Vulnerabilities Up 20%, MCP Risks Surge 270%.html·Oct 30, 2025
APIVulnerabilities

In Q3 2025, authorization issues made up 28% of all API vulnerabilities.

WallarmWallarm Releases Q3 2025 API ThreatStats Report: API Vulnerabilities Up 20%, MCP Risks Surge 270%.html·Oct 30, 2025
APIVulnerabilities

In Q3 2025, Model Context Protocol vulnerabilities surged by 270% compared to Q2 2025.

WallarmWallarm Releases Q3 2025 API ThreatStats Report: API Vulnerabilities Up 20%, MCP Risks Surge 270%.html·Oct 30, 2025
APIVulnerabilities

In Q3 2025, there were 1,602 disclosed API-related vulnerabilities, representing a 20% increase from Q2 2025.

WallarmWallarm Releases Q3 2025 API ThreatStats Report: API Vulnerabilities Up 20%, MCP Risks Surge 270%.html·Oct 30, 2025
APIVulnerabilities

In Q3 2025, 16% of vulnerabilities added to CISA's Known Exploited Vulnerabilities catalog were API-related.

WallarmWallarm Releases Q3 2025 API ThreatStats Report: API Vulnerabilities Up 20%, MCP Risks Surge 270%.html·Oct 30, 2025
APIVulnerabilities

In Q3 2025, Security Misconfiguration accounted for 38% of all API flaws, rising by 33% from Q2 2025.

WallarmWallarm Releases Q3 2025 API ThreatStats Report: API Vulnerabilities Up 20%, MCP Risks Surge 270%.html·Oct 30, 2025
APIVulnerabilities

In Q3 2025, AI-API vulnerabilities increased by 57%, driven by a 270% rise in Model Context Protocol vulnerabilities.

WallarmWallarm Releases Q3 2025 API ThreatStats Report: API Vulnerabilities Up 20%, MCP Risks Surge 270%.html·Oct 30, 2025
APIVulnerabilities

Of the 2,869 security issues analysed in Agentic AI projects, the majority were API-related (65%).

WallarmThe Rise of Agentic AI API ThreatsStats Report Q1 2025·Apr 24, 2025
AIAgentic AIAPI

25% of reported security issues in Agentic AI remain open.

WallarmThe Rise of Agentic AI API ThreatsStats Report Q1 2025·Apr 24, 2025
AIAgentic AIVulnerabilities

60% of top vulnerabilities found in Agentic AIwere access control-related

WallarmThe Rise of Agentic AI API ThreatsStats Report Q1 2025·Apr 24, 2025
AIAgentic AIVulnerabilities

Some open security issues in Agentic AI are lingering for 1,200-plus days.

WallarmThe Rise of Agentic AI API ThreatsStats Report Q1 2025·Apr 24, 2025
AIAgentic AIVulnerabilities

Over 700 issues in Agentic AI repositories remain unaddressed.

WallarmThe Rise of Agentic AI API ThreatsStats Report Q1 2025·Apr 24, 2025
AIAgentic AIVulnerabilities

API-related data breaches tripled in 2024.

Wallarm2025 API ThreatStats Report·Jan 1, 2025
APIData BreachSecurityRisk

There was an average of three API-related breaches per month in 2024, with some months seeing as many as five to seven.

Wallarm2025 API ThreatStats Report·Jan 1, 2025
APIData BreachFrequencyRisk

In 2024, there was an average of three monthly API-related breach incidents—and, at times, as many as five to seven breaches each month.

WallarmAI Security Is API Security·Jan 1, 2025

Machine learning-based discovery tools often identify 31% more API endpoints than those reported by enterprises.

Wallarm2025 API ThreatStats Report·Jan 1, 2025
AIAPIVulnerabilityAuthentication

18.9% of API-related exploits involved legacy APIs, including AJAX backends and URL parameter-based systems.

Wallarm2025 API ThreatStats Report·Jan 1, 2025
APILegacy SystemsExploitsSecurity

Only 11% of AI-powered APIs implemented robust security measures, such as bearer tokens with expiration times.

Wallarm2025 API ThreatStats Report·Jan 1, 2025
AIAPIAuthenticationSecurity

Wallarm's researchers tracked 439 AI-related CVEs, a 1,025% increase from the prior year. Nearly all (99%) were directly tied to APIs.

WallarmAI Security Is API Security·Jan 1, 2025

Newly published API endpoints are discovered by attackers in a mere 29 seconds.

Wallarm2025 API ThreatStats Report·Jan 1, 2025
WallarmAPIEndpointAttack DetectionSpeed

Traditional API security systems can take 5-10 minutes to detect and remediate threats.

Wallarm2025 API ThreatStats Report·Jan 1, 2025
WallarmAPI SecurityThreat DetectionRemediation SpeedTraditional Systems

Wallarm tracked 439 AI-related CVEs in 2024.

Wallarm2025 API ThreatStats Report·Jan 1, 2025
AICVEAPIVulnerabilities

33.5% of the API-related exploits targeted modern APIs, like RESTful and GraphQL.

Wallarm2025 API ThreatStats Report·Jan 1, 2025
APIExploitRESTfulGraphQL

21.5% of AI vulnerabilities are indirectly tied to APIs, including flaws in third-party integrations.

Wallarm2025 API ThreatStats Report·Jan 1, 2025
WallarmAIVulnerabilityThird-party IntegrationsAPI

Kernel exploits accounted for 5.4% of the CISA KEV exploits.

Wallarm2025 API ThreatStats Report·Jan 1, 2025
WallarmExploitsKernel ExploitsCISA KEVRisk

Mobile exploits accounted for 5.9% of the CISA KEV exploits.

Wallarm2025 API ThreatStats Report·Jan 1, 2025
WallarmExploitsMobile ExploitsCISA KEVRisk

Legacy APIs in web applications represent over 18% of exploited vulnerabilities.

WallarmAI Security Is API Security·Jan 1, 2025

AI vulnerabilities increased by 1,025% from 2023 to 2024.

Wallarm2025 API ThreatStats Report·Jan 1, 2025
AIVulnerabilityAPIRisk

Over 50% of exploits in CISA’s Known Exploited Vulnerabilities (KEV) report were API-related in 2024, up from 20% in 2023.

Wallarm2025 API ThreatStats Report·Jan 1, 2025
APIVulnerabilityExploitsSecurity

35% of enterprises are just beginning their AI journey.

Wallarm2025 API ThreatStats Report·Jan 1, 2025
AIEnterpriseDeploymentSecurity readiness

63% of enterprise leaders believe AI increases API security risk.

Wallarm2025 API ThreatStats Report·Jan 1, 2025
AIAPISecurity RiskEnterprise Leaders

77.4% of API-related vulnerabilities in AI products are directly API-related, such as weak API authentication, inadequate rate limiting, and broken access controls.

Wallarm2025 API ThreatStats Report·Jan 1, 2025
WallarmAIAPIVulnerabilityAuthentication

Attackers can exfiltrate sensitive data in as little as 6 seconds in API attacks.

Wallarm2025 API ThreatStats Report·Jan 1, 2025
WallarmAPIData ExfiltrationAttack SpeedRisk

Only 1.1% of the vulnerabilities in AI products were entirely unrelated to APIs.

Wallarm2025 API ThreatStats Report·Jan 1, 2025
WallarmAIVulnerabilityNon-APIProduct Vulnerabilities

Browser exploits accounted for 9.2% of the CISA KEV exploits.

Wallarm2025 API ThreatStats Report·Jan 1, 2025
WallarmExploitsBrowser ExploitsCISA KEVRisk

57% of AI-powered APIs were externally accessible, and 89% relied on insecure authentication mechanisms.

WallarmAI Security Is API Security·Jan 1, 2025

12% of enterprises are waiting for security controls to be ready before deploying AI.

Wallarm2025 API ThreatStats Report·Jan 1, 2025
AIEnterpriseDeploymentSecurity Controls

54% of enterprises report engaging in multiple AI deployments.

Wallarm2025 API ThreatStats Report·Jan 1, 2025
AIEnterpriseDeploymentTechnology

Over 53% of enterprise leaders surveyed reported engaging in multiple AI deployments.

WallarmAI Security Is API Security·Jan 1, 2025