Report by Sonatype
The AI-Era Software Assembly Line
Key Findings
The median age of unresolved Critical and High vulnerabilities fell to 103 days by May 2026.
For vulnerable dependencies introduced into AI-era applications, a materially lower-risk npm version was already available 46.9% of the time when the dependency was selected.
For vulnerable dependencies introduced into AI-era applications, a materially lower-risk PyPI version was already available 34.3% of the time when the dependency was selected.
Average Critical and High-severity vulnerabilities per analyzed application increased from 14.14 in June 2022 to 54.3 by 2026.
Median vulnerability age fell 59% from its January 2024 peak.
The median age of unresolved Critical and High vulnerabilities decreased by 45%, dropping from 228 days to 126 days during the AI era.
Among early AI-era Critical and High vulnerability cohorts with at least 12 months to remediate, 52.6% were resolved, 44.3% remained open, and 3.1% were waived.
Even after excluding newly managed legacy applications, Critical and High vulnerability risk per application increased 3.91x.
Critical and High-severity vulnerabilities per enterprise application increased 4.31x.
Newly affected software component versions increased at 46 times the pre-AI rate.