Report by Contrast Security
AppSec Overflow 2026
Key Findings
An average of 42 monthly attacks per application are viable, meaning exploitation attempts reach and trigger real vulnerable code.
More than 60% of applications see fewer than 3,000 attacks per month.
More than a quarter of applications absorb upward of 30,000 attacks per month.
SQL injection appears in the top five viable attack techniques for every industry vertical analyzed.
Critical vulnerabilities in custom code take an average of 92 days to remediate.
Three AI scanners analyzing the same codebase agree on only 5% of findings.
Attackers touch the average application 11,382 times per month, roughly once every four minutes.
The average application carries 106 vulnerability findings, including 22 rated High or Critical.
54% of CVE instances observed in third-party production code come from CVEs published more than a year ago.
Scanning a 2 million-line codebase consumes roughly $315 in tokens while triaging the resulting findings costs approximately $128,000.
A single AI scanner reproduces only 17% of its own findings when run three times against the same code.