Report by Cobalt

State of Pentesting Report 2026

10 FINDINGSPublished Apr 21, 2026
View Original Report →

Key Findings

97% of security professionals state they are adding AI capabilities to their software and services.

AI AdoptionSoftware Development

The typical organization ultimately resolves 86% of its high-risk findings, but only 52% of high-risk findings are remediated within a five-year time frame.

Vulnerability RemediationLong-Term Remediation

LLMs have the lowest resolution rate of all application types, with just 38% of high-risk issues being fixed.

LLM TestingVulnerability Remediation

One in five organizations experienced an LLM security incident in the last year, while a further 18% are unsure and 19% preferred not to answer.

Security IncidentsLLM Security IncidentOrganizational Risk

57% of C-suite executives believe their organization consistently meets remediation SLAs, yet only 15% of security practitioners agree.

GovernanceSLAsSecurity Operations

33% of organizations reported significant security budget growth in the past year, while 50% saw incremental increases.

Security BudgetsFundingRisk Management

Security teams' confidence in their ability to keep up with the security implications of AI adoption declined from 64% to 51%.

Security ConfidenceAI SecurityAI Adoption

Top-performing organizations have a high-risk finding half-life of 10 days, while bottom-tier organizations have a 249-day half-life—an eight-month gap in exposure.

Vulnerability RemediationRisk ExposureOperational Performance

32% of AI/LLM findings are rated as high risk, nearly 2.7x the overall high-risk rate of 12%.

AI TestingLLM TestingVulnerabilities

61% of security professionals want a "strategic pause" to calibrate defenses against AI-driven threats, up from 48% last year.

AI SecurityAI-Driven ThreatsSecurity Strategy