Report by Cobalt
State of Pentesting Report 2026
Key Findings
97% of security professionals state they are adding AI capabilities to their software and services.
The typical organization ultimately resolves 86% of its high-risk findings, but only 52% of high-risk findings are remediated within a five-year time frame.
LLMs have the lowest resolution rate of all application types, with just 38% of high-risk issues being fixed.
One in five organizations experienced an LLM security incident in the last year, while a further 18% are unsure and 19% preferred not to answer.
57% of C-suite executives believe their organization consistently meets remediation SLAs, yet only 15% of security practitioners agree.
33% of organizations reported significant security budget growth in the past year, while 50% saw incremental increases.
Security teams' confidence in their ability to keep up with the security implications of AI adoption declined from 64% to 51%.
Top-performing organizations have a high-risk finding half-life of 10 days, while bottom-tier organizations have a 249-day half-life—an eight-month gap in exposure.
32% of AI/LLM findings are rated as high risk, nearly 2.7x the overall high-risk rate of 12%.
61% of security professionals want a "strategic pause" to calibrate defenses against AI-driven threats, up from 48% last year.