Report by TuxCare

2026 Open Source Landscape Report

25 FINDINGSPublished Feb 18, 2026
View Original Report →

Key Findings

33.33% of respondents reported using two versions of CentOS despite all stable versions now years into end of life.

Open SourceCentOSEOL

47.8% of surveyed enterprise open source users said their organization experienced a cybersecurity incident in the past 12 months.

Open SourceCybersecurity Incident

Open source using organizations with 1,001–10,000 employees were more than twice as likely to report an incident compared to those with fewer than 100 employees.

Open SourceCybersecurity Incident

Among the open-source users whose organizations reported a cybersecurity incident, 61.4% indicated that the incident occurred when a patch was available but had not been applied – a slight increase from 60.4% last year.

Open SourceCybersecurity IncidentVulnerabilitiesPatching

Among respondents who identified at least one affected technology, vulnerabilities tied to reported open source incidents were distributed across infrastructure and middleware (51.9%), software development frameworks and libraries (50.0%), and databases and data technologies (48.1%).

Open SourceCybersecurity IncidentVulnerabilitiesPatching

When open source using organizations were asked if they took steps to improve its patch and vulnerability management processes in the last 12 months, 68.8% said they increased automation.

Open SourceVulnerability ManagementPatchingAutomation

When open source using organizations were asked if they took steps to improve its patch and vulnerability management processes in the last 12 months, 44.8% said they conducted security training.

Open SourceVulnerability ManagementPatchingSecurity Training

When open source using organizations were asked if they took steps to improve its patch and vulnerability management processes in the last 12 months, 23.0% said they increased IT security staff.

Open SourceVulnerability ManagementPatchingIT Security StaffTalent

When open source using organizations were asked if they took steps to improve its patch and vulnerability management processes in the last 12 months, 18.4% said they adopted AI/machine learning.

Open SourceVulnerability ManagementPatchingAIMachine Learning

48.5% of surveyed organizations said there was no change in the last 12 months in the time required for patching a critical or high-priority Linux vulnerability once it was detected.

Open SourceVulnerability ManagementPatchingLinux

For of open-source users on enterprise teams, the greatest enemy of security is the uptime mandate.

Open SourceEnterpriseUptime

At least 43% of enterprises that use open-source technology report a mechanism in place to monitor whether those technologies are active, in maintenance, or EOL (7.5%do not track; 4.2% are unsure).

Open SourceEnterpriseEOL

Organizations relying on public project documentation are most strongly represented among those discovering EOL during regular dependency reviews (57.1%).

Open SourceEOL

Organizations in the 1,001–5,000 employee band are the most reactive, with 69.1% discovering EOL status only after something breaks or a vendor notifies them.

Open SourceEOL

Teams that surface EOL through dependency reviews (74.3%) or security scanning (69.7%) most often choose upgrades, suggesting planned remediation is more feasible when signals arrive earlier.

Open SourceEOLDependency ReviewsSecurity Scanning

When EOL is identified through breakage or compatibility failures, reliance on ELS/vendor patching rises (59.7%) while upgrades are least common (18.2%).

Open SourceEOL

A majority of surveyed organizations report using fewer than 100 direct open-source projects or libraries in production, with the largest share (~35%) clustered between 25 and 99.

Open SourceOpen-Source ProjectsOpen-Source Libraries

5.56% of respondents reported using all three versions of CentOS despite all stable versions now years into end of life.

Open SourceCentOSEOL

Roughly two-thirds (65.7%) of businesses spend 10 hours or less per month on Linux maintenance.

Open SourceLinux Maintenance

When open source using organizations were asked if they took steps to improve its patch and vulnerability management processes in the last 12 months, 63.2% said they reviewed/updated internal vulnerability management processes.

Open SourceVulnerability ManagementPatchingVulnerability Management Process

Only 1% of organizations said they decreased the time required for patching a critical or high-priority Linux vulnerability after it was detected.

Open SourceVulnerability ManagementPatchingLinux

Nearly one in four organizations operates on a "skeleton crew" of open-source projects.

Open SourceOpen-Source Projects

41.67% of CentOS users report that they're migrating / planning to migrate.

Open SourceCentOSEOL

41.67% of CentOS users report purchasing or planning to purchase extended support.

Open SourceCentOSEOL

92.6% of open-source users reported that their organization was aware it was vulnerable before the cybersecurity incident occurred.

Open SourceCybersecurity IncidentVulnerabilitiesPatching