Public sector software, from defense platforms to K-12 student information systems, is accumulating a dangerous backlog of unresolved vulnerabilities. That’s the headline finding from Veracode’s 2026 State of Software Security report, and the data behind it is unambiguous: the pace of vulnerability discovery has structurally outrun the capacity to fix them.
Veracode’s analysis of 1.6 million applications and 141 million security findings reveals what public sector technology leaders need to know, and do, right now. The short version: 60% of organizations now carry critical security debt, a 20% jump in a single year. These aren’t routine maintenance tasks aging past their due date. They’re the most severe, most exploitable flaws in the portfolio, and the amount being left unresolved for over a year are piling up.
Detection is no longer enough. The next era of public sector cybersecurity must be defined by remediation.
The math that should worry every public sector agency
Fix capacity for the median organization sits at roughly 10% of discovered flaws per month. That sounds manageable until you do the arithmetic: if an organization discovers 1,000 vulnerabilities and resolves 100, the backlog shrinks… but only if fewer than 100 new vulnerabilities arrive in that same month. They don’t. New features, dependency updates, and AI-generated code introduce more than that, and the backlog grows.
The result is a median 243-day fix half-life, the time it takes to close half of all discovered flaws across every scan type. That figure is moving in the right direction, but glacially, and it remains an order of magnitude slower than what federal mandates require.
Under CISA’s BOD 26-04 — which in 2026 revoked and replaced the prior BOD 22-01 — federal agencies must remediate KEV-catalog vulnerabilities on a risk-based timeline: two weeks for most known exploited vulnerabilities (CVEs assigned 2021 or later), and as little as three days for the highest-risk entries requiring forensic triage. That two-week default is roughly 17 times faster than the 243-day median the average organization currently achieves across all vulnerability levels. Even accounting for the difference in scope — the mandate covers only KEV-listed flaws, while the half-life spans all flaw types — the gap between requirement and reality is stark. This is a compliance risk, not just an operational one.
Where the risk actually lives
If you want to know where the hardest problems are, follow the third-party code. 66% of the most dangerous, long-lived vulnerabilities in the average application portfolio originate in third-party components. This is software that agencies didn’t develop and can’t directly control. That share is actually down from 70% the prior year, reflecting growing adoption of SBOMs and dependency hygiene, but it still represents the dominant source of critical risk.
And those flaws are the slowest to fix. The half-life of third-party flaws identified through Software Composition Analysis (SCA) is 358 days. That’s nearly a full year, and 115 days longer than the average across all scan types.
This is why point-in-time attestation is insufficient. OMB M-26-05 preserves the right to require current SBOMs from vendors upon request — but having the right and exercising it are different things. Agencies should exercise it systematically for high-criticality systems and require continuous SCA monitoring rather than annual assessments.
AI’s double edge
The 2026 data reveals a dangerous new dynamic: the rise of AI-assisted code generation is likely introducing new patterns of high-risk vulnerabilities into the software supply chain, even as AI-driven remediation tools are beginning to offer a credible path out of the debt accumulation cycle.
The evidence is building. Veracode’s data identified a 36% relative increase in the concentration of vulnerabilities that are simultaneously high in both severity and exploitability — what the report terms the “high-risk region” — rising from 8.3% to 11.3% of all findings. This surge is believed to be at least partially attributable to the proliferation of AI-assisted code generation tools in development pipelines.
A finding from Veracode’s 2026 GenAI Code Security Report underscores the risk: in 85% of tests, AI-generated code failed security tests for cross-site scripting (XSS) — a vulnerability class particularly dangerous in public-facing web portals handling student data, benefit applications, or permit submissions.
But the same capabilities creating new vulnerability patterns are also enabling a step-change in remediation velocity. The bulk of security debt consists of common, repetitive patterns — SQL injection, cross-site scripting, insecure configurations, outdated dependencies — that AI-assisted remediation tools can address at scale with minimal developer effort. Deploying these tools, and allocating dedicated sprint capacity to AI-assisted debt reduction, offers a realistic path to doubling fix capacity without proportional cost increases.
Can AI help close the gap? In the right environments, yes. But public-sector teams will still require clear controls over data handling, deployment model, and approval path before AI-enabled tooling can be used broadly. The opportunity is real; the guardrails are non-negotiable.
The SLED pressure cooker
If federal agencies are stretched, State, Local, and Education (SLED) organizations are under siege. SLED teams manage enterprise-scale software portfolios — student information systems, benefits administration platforms, public safety systems, permitting applications — with technology teams a fraction of the size of their private-sector counterparts.
The threat is escalating on every axis: cyber attacks on education surged 63% (Nov 2024–Oct 2025)and 251 ransomware attacks hit educational institutions in 2025, breaching more than 3.96 million records — a 27% increase in breached data year-over-year.
The attackers targeting these organizations are not, in most cases, deploying novel zero-day exploits. They are finding and exploiting the class of known, unresolved, highly exploitable vulnerabilities that the data shows accumulating in every organization’s portfolio. These are not accidents. They are the predictable consequences of critical security debt remaining unresolved.
The resource gap compounds the problem. 61% of K-12 school districts rely on general funds rather than dedicated cybersecurity budgets. Meanwhile, new state cybersecurity laws in 2026 are requiring K-12 districts to implement multi-factor authentication, network segmentation, and zero-trust principles — whether or not federal funding is available to support compliance. Cyber insurers have raised the bar too, now requiring documented, demonstrable security controls before issuing or renewing policies.
The mandates are aligned. The capacity is not.
For the first time, the policy environment is providing the mandate structure to make this shift real:
- BOD 26-04 (which revoked BOD 22-01) sets risk-based remediation velocity standards — two weeks for most KEV vulnerabilities — that exceed what manual-only programs can achieve.
- OMB M-26-05 creates procurement pressure for continuous supply chain visibility.
- State legislative mandates are extending application security requirements into K-12 districts and municipalities historically underserved by federal frameworks.
- Cyber insurance requirements are creating financial accountability for organizations that cannot demonstrate systematic programs.
The data, the mandates, and the tooling are aligned. What’s missing is treating remediation capacity as a strategic investment, not a line item to be optimized away.
What public sector leaders should do in 2026
Drawing on the 2026 SoSS data and the current federal regulatory environment, these are the highest-priority steps for public sector technology leaders:
- Prioritize by exploitability, not just severity. CVSS-score-only prioritization fails to capture which vulnerabilities are actively exploitable in your specific environment. Move to an exploitability-weighted framework that correlates SAST, DAST, and SCA findings with runtime and business context. This is essential for meaningful BOD 26-04 compliance – the directive is explicitly risk-based, rewarding organizations that can demonstrate prioritization by real exploitability rather than raw CVSS scores.
- Exert procurement leverage on supply chain risk. With third-party components representing 66% of critical security debt and a 358-day remediation timeline, point-in-time attestation is insufficient. Agencies should systematically require current SBOMs from vendors for high-criticality systems and mandate continuous SCA monitoring rather than annual assessments.
- Deploy AI-assisted remediation at scale. The 243-day median fix half-life is incompatible with BOD 26-04’s two-week remediation mandate for most KEV vulnerabilities. AI-assisted remediation – automated fix suggestions with human review – is the only scalable path to compliance-grade velocity without proportional staffing expansion. But broad deployment requires clear controls over data handling, deployment model, and approval path before AI-enabled tooling can be used broadly. Establish those controls, then allocate dedicated sprint capacity for AI-assisted debt reduction as a standard development process requirement.
- Scan AI-assisted development pipelines. Contractor teams adopting AI code generation without security guardrails are likely introducing new high-severity vulnerability patterns into agency systems. Update contractor SSDF attestation requirements to require security scanning coverage of AI-assisted pipelines, and add AI code vulnerability patterns to security training.
- Shift security left into developer workflows. The most cost-effective approach to security debt is preventing it from accumulating. Integrate automated scanning and fix suggestions directly into developer workflows before code reaches production.
- Make security debt a leadership KPI. Security debt should be tracked and reported at the program executive level alongside mission assurance metrics — not buried in technical vulnerability backlogs. When debt becomes a KPI tied to OKRs and contractor performance, the urgency and budget for systematic remediation follow.
The inflection point
The 2026 findings are not a story of failure. They are a story of a sector at an inflection point. The organizations achieving top-quartile security performance are not doing so through brute-force manual remediation. They are investing in automation, deploying AI-assisted fix capabilities, using risk-based prioritization to focus limited capacity on the vulnerabilities that matter most, and establishing governance structures that hold security outcomes accountable at the leadership level.
The detection era built visibility. The remediation era will build trust in the software, in the supply chain, and in the institutions that depend on both. Public sector organizations that make that investment in 2026 will be materially better positioned to protect citizen data, maintain mission continuity, and meet the accountability standards their constituents and regulators increasingly demand.
The security debt crisis is solvable. The question is whether the public sector treats remediation as the strategic priority the data says it has become.
Read the full report: Veracode 2026 State of Software Security — Public Sector Edition
This article is for informational purposes only and does not constitute legal, technical, or other professional advice. © Veracode 2026. All rights reserved.