Vulnerabilities Exploited in Hours, Patches Accumulating Years of Delay
Software vulnerabilities turn into active exploits in just a few hours, while application security teams manage patch backlogs dating back years. This is the alarming picture that emerged from Contrast Security's AppSec Overflow 2026 report, based on telemetric data collected from hundreds of thousands of applications and APIs in production.
Quick Response
Applications suffer attacks every four minutes, with 42 confirmed exploitation attempts per month. The most critical vulnerabilities take an average of 92 days to resolve. Only 5% of AI security findings are shared across different tools. Companies manage an average of 106 vulnerabilities per application, with 22 classified as critical or high severity.
Constant Attacks and Exploitation Techniques
Adversaries interact with average applications every four minutes, with most traffic consisting of automated reconnaissance activity. Contrast Security recorded 42 confirmed exploitation attempts per application each month, with vulnerabilities actually triggered. Untrusted deserialization emerged as the most common attack technique, followed by path traversal and method tampering. SQL injection was detected among the top five attack techniques in all sectors analyzed, from finance to healthcare to manufacturing.
Patch Backlogs Extending for Months
Applications monitored by Contrast have an average of 106 vulnerabilities, with 22 classified as critical or high severity. Development and security teams resolve only a few of these each month. Fixing a critical vulnerability takes an average of 92 days, with an average removal rate of 3.4 vulnerabilities per application per month. Known vulnerabilities such as Spring4Shell (CVE-2022-22965) and Log4Shell continue to appear in production telemetry, despite being discovered years ago.
The Impact of AI on Application Security
Jeff Williams, CTO of Contrast Security, observed that AI has radically changed the landscape of application security. "For twenty years, the discipline of AppSec has been organized around a race: find the vulnerability, decide if it's important, and fix it before someone with bad intentions finds it first. AI has ended this race, and the defenders have lost it. Now we see vulnerabilities turned into weapons in hours, while the average fix for a critical vulnerability takes weeks or months."
Bug Bounty Programs in Retreat
Zero Day Clock, which aggregates exploitation signals from over 83,000 CVEs, recorded an average exploitation time of over two years in 2018. This value dropped below one year in 2021, and most vulnerabilities exploited in 2025 were turned into weapons within three weeks. HackerOne suspended new subscriptions to the Internet Bug Bounty program in March 2026, and Node.js discontinued its bounty program shortly after, citing loss of funding.
AI Changes the Equation on Both Sides
Contrast Security tested three AI scanners on the same code and discovered that they agreed on only 5% of the findings. Running a scanner three times on the same code reproduced only 17% of its own findings. Scanning a codebase of 2 million lines with AI tools cost approximately $315 in API fees, while triaging the results cost approximately $128,000. David Lindner, CISO of Contrast Security, observed that "AI won't solve this problem, and we have the data to prove it."
Contrasting Data on Severity and Exploitation Probability
CVSS severity scores and EPSS exploitation probability scores each provide significant signals. Among CVEs in CISA's Known Exploited Vulnerabilities catalog, 82% had an EPSS score of 90% or higher. Two CVEs in the dataset, CVE-2006-1547 and CVE-2023-38180, each had a CVSS score of 7.5 but different EPSS scores. More than 60% of vulnerabilities with a CVSS score of 7.5 or higher had an EPSS score of less than 10%. Over 50% of vulnerabilities with a CVSS score below 7.5 had an EPSS score of over 10%.
The Future of Application Security
The future of application security will see an increase in the use of AI-based tools, but also a return to a deep understanding of application behavior and attack techniques. Organizations that can balance technological innovation with a fundamental understanding of security will be best positioned to address future challenges. Additionally, collaboration among different industry players, including tool vendors, security researchers, and user organizations, will be crucial to addressing common challenges.
Legal and Regulatory Challenges
As attacks on applications increase, governments and regulatory bodies are paying more attention to application security. Regulations such as GDPR in Europe and other data protection laws around the world are imposing stricter requirements for application security. Organizations must not only address technical threats but also navigate an evolving regulatory landscape that can result in severe penalties for non-compliance.
The Importance of Operational Resilience
In a context where vulnerabilities can be exploited in just a few hours, operational resilience becomes a critical factor. Organizations must be able to detect attacks quickly, respond effectively, and restore services as soon as possible. This requires not only advanced technologies but also well-defined processes and an organizational culture that values security and resilience.
The Evolution of the Security Tools Market
The market for application security tools is rapidly evolving, with new players entering the sector and existing vendors adapting. Organizations must carefully evaluate the available options, considering not only technical features but also integration with their existing environments and the support provided by vendors. Choosing the right tools can make a significant difference in an organization's ability to manage security threats.
The Role of the Security Community
The application security community, which includes researchers, professionals, and enthusiasts, plays a crucial role in improving overall security. Sharing information, collaborating on research projects, and organizing events such as conferences and workshops are essential to addressing common challenges. Organizations should be active in the security community, not only to access information and resources but also to contribute with their experiences and expertise.
As the landscape of application security becomes increasingly complex and dynamic, organizations must adopt a holistic approach that integrates advanced technology, human expertise, and an organizational culture that values security. Only in this way can they address current and future challenges and effectively protect their applications and sensitive data.
Editorial Note and Disclaimer
The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.
GoYou does not constitute a journalistic publication nor an editorial product pursuant to Law No. 62/2001 and does not perform real-time information activities.
The GoYou project does not provide professional, technical, legal, or financial advice and disclaims any liability for the improper use of the information published.
In the Crypto sector, every investment involves risks: readers are invited to always inform themselves independently before making any decision.