Report by Veracode
2026 State of Software Security Report: Prioritize, Protect, Prove
6 FINDINGSPublished Feb 24, 2026
View Original Report →Key Findings
Critical security debt, defined as risky vulnerabilities older than a year, increased 20% year-over-year.
Security DebtVulnerabilitiesRisk Management
11.3% of software flaws pose real-world danger.
VulnerabilitiesRisk Prioritization
High-risk vulnerabilities (flaws that are both severe and highly exploitable) increased 36% year-over-year.
High-Risk VulnerabilitiesExploitabilityRisk Management
82% of organizations now harbor security debt, an 11% increase from the prior year.
Security DebtVulnerabilities
Third-party libraries and open-source dependencies account for 66% of the most dangerous, longest-lived vulnerabilities.
Open Source RiskThird-Party RiskVulnerabilitiesSecurity Debt
60% of organizations with security debt have security debt defined as "critical," representing vulnerabilities severe enough to cause catastrophic damage if exploited.
Security DebtCritical VulnerabilitiesRisk Management