Report by Orca Security

2026 State of Application Security Report

17 FINDINGSPublished Apr 7, 2026
View Original Report →

Key Findings

11.92% of organizations have exposed Databricks credentials.

AI SecuritySecrets ManagementDatabricks Credentials

24.82% of repositories predate GitHub’s 2023 default token hardening and may retain legacy access settings.

RepositoriesAccess ControlGitHub

28.49% of organizations have exposed Hugging Face tokens.

AI SecuritySecrets ManagementThird-Party ServicesHugging Face

Nearly one-third of organizations expose valid secrets in code.

Secrets ManagementApplication SecuritySecrets Exposure

18.39% of organizations have exposed OpenAI credentials.

AI SecuritySecrets ManagementOpenAICredential Exposure

11.01% of organizations have active malicious packages embedded in production environments.

MalwareMalicious Packages

10.10% of organizations have exposed Anthropic credentials.

AI SecuritySecrets ManagementAnthropicCredential Exposure

30.60% of repositories do not require signed commits.

RepositoriesCode Integrity

29.15% of organizations are vulnerable to the React2Shell RCE vulnerability.

VulnerabilitiesReact2Shell RCE Vulnerability

57.87% of organizations have IAM users without MFA.

IAM Access ControlAuthenticationMFA

More than 81% of organizations deploy vulnerable dependencies.

Vulnerable DependenciesVulnerabilitiesSoftware Dependencies

41.88% of production organizations have leaked AI or ML credentials.

AI SecuritySecrets ManagementCloud SecurityAI Credential LeakML Credential Leak

Over 77% of organizations leave high or critical container vulnerabilities unpatched for more than 90 days.

ContainersVulnerability ManagementContainer VulnerabilitiesPatch ManagementCritical Vulnerabilities

26.35% of repositories require no code review before merging.

Code ReviewRepositories

80% of organizations lack proper logging in infrastructure as code.

Infrastructure as CodeLogging

46.20% of organizations remain exposed to Log4Shell years after disclosure.

VulnerabilitiesLog4ShellSupply Chain Attacks

21.68% of organizations maintain overly permissive CI/CD token permissions.

CI/CD Token PermissionsAccess Control