Report by Sonatype

The AI-Era Software Assembly Line

10 FINDINGSPublished Aug 18, 2026
View Original Report →

Key Findings

The median age of unresolved Critical and High vulnerabilities fell to 103 days by May 2026.

VulnerabilitiesRemediation

For vulnerable dependencies introduced into AI-era applications, a materially lower-risk npm version was already available 46.9% of the time when the dependency was selected.

Dependency ManagementnpmOpen SourceVulnerabilities

For vulnerable dependencies introduced into AI-era applications, a materially lower-risk PyPI version was already available 34.3% of the time when the dependency was selected.

Dependency ManagementPyPIOpen SourceVulnerabilities

Average Critical and High-severity vulnerabilities per analyzed application increased from 14.14 in June 2022 to 54.3 by 2026.

Vulnerabilities

Median vulnerability age fell 59% from its January 2024 peak.

VulnerabilitiesRemediation

The median age of unresolved Critical and High vulnerabilities decreased by 45%, dropping from 228 days to 126 days during the AI era.

VulnerabilitiesRemediationTime-to-Fix

Among early AI-era Critical and High vulnerability cohorts with at least 12 months to remediate, 52.6% were resolved, 44.3% remained open, and 3.1% were waived.

VulnerabilitiesRemediation

Even after excluding newly managed legacy applications, Critical and High vulnerability risk per application increased 3.91x.

VulnerabilitiesLegacy Systems

Critical and High-severity vulnerabilities per enterprise application increased 4.31x.

VulnerabilitiesEnterprise ApplicationsSoftware Security

Newly affected software component versions increased at 46 times the pre-AI rate.

Dependency ManagementVulnerabilitiesOpen Source