Report by Orca Security
2026 State of Application Security Report
Key Findings
11.92% of organizations have exposed Databricks credentials.
24.82% of repositories predate GitHub’s 2023 default token hardening and may retain legacy access settings.
28.49% of organizations have exposed Hugging Face tokens.
Nearly one-third of organizations expose valid secrets in code.
18.39% of organizations have exposed OpenAI credentials.
11.01% of organizations have active malicious packages embedded in production environments.
10.10% of organizations have exposed Anthropic credentials.
30.60% of repositories do not require signed commits.
29.15% of organizations are vulnerable to the React2Shell RCE vulnerability.
57.87% of organizations have IAM users without MFA.
More than 81% of organizations deploy vulnerable dependencies.
41.88% of production organizations have leaked AI or ML credentials.
Over 77% of organizations leave high or critical container vulnerabilities unpatched for more than 90 days.
26.35% of repositories require no code review before merging.
80% of organizations lack proper logging in infrastructure as code.
46.20% of organizations remain exposed to Log4Shell years after disclosure.
21.68% of organizations maintain overly permissive CI/CD token permissions.