Report by Wallarm

API ThreatStats Report 2026

11 FINDINGSPublished Feb 17, 2026
View Original Report →

Key Findings

In 2025, 36% of AI-related KEVs involved an API attack surface.

AI-related VulnerabilitiesAPI SecurityAI-related KEVsKEVsAPI Attack Surface

99% of API vulnerabilities are remotely exploitable.

API SecurityRemote ExploitationAPI VulnerabilitiesVulnerabilities

In 2025, 17% of 67,058 published vulnerabilities (11,053 vulnerabilities) were API-related.

API SecurityVulnerabilitiesAPI Vulnerabilities

In 2025, 43% of CISA KEV additions were API-related, making APIs the single largest exploited surface in that dataset.

API SecurityAPIsKEV

In 2025, 36% of AI-related vulnerabilities involved APIs (786 of 2,185 AI-related vulnerabilities).

AI-related VulnerabilitiesAPI SecurityAPIs

In 2025, 14% of published AI vulnerabilities were MCP-related (315 MCP-related vulnerabilities).

AI VulnerabilitiesModel Context ProtocolVulnerabilities

97% of API vulnerabilities can be exploited with a single request.

API SecurityExploitabilityAPI VulnerabilitiesVulnerabilities

MCP vulnerabilities grew 270% from Q2 to Q3 in 2025.

AI SecurityModel Context ProtocolMCP VulnerabilitiesVulnerabilities

98% of API vulnerabilities are easy or trivial to exploit.

API SecurityExploitabilityVulnerabilities

59% of API vulnerabilities require no authentication.

API SecurityAuthenticationAPI VulnerabilitiesVulnerabilities

In 2025 breach data, AI platforms and tooling accounted for 15% of API-related breaches, tying software as the largest category in the dataset.

Data BreachesAI PlatformsAPI Security