Securing the Public Sector in 2026: The Security Debt Crisis
Demands Action Now

Pubsec SOSS Compliance

82% of organizations carry security debt – known vulnerabilities sitting unresolved for over a year – and critical security debt surged 20% in a single year, now hitting 60% of organizations. Nation-state actors, ransomware groups, and opportunistic attackers go after precisely this class of flaw: highly severe, highly exploitable, and sitting open. This report translates Veracode’s 2026 State of Software Security findings into a concrete framework for Federal agencies and SLED organizations to prioritize, remediate, and get ahead of the threats.

What’s Inside

Key Insights:

Critical Security Debt Is Up 20% in One Year

The most weaponizable flaws – highly severe, highly exploitable, unresolved for over a year – now affect 60% of organizations, giving nation-state actors and ransomware groups a larger and more dangerous attack surface than a year ago.

Third-Party Code Is Where the Worst Debt Lives

66% of the most dangerous, longest-lived vulnerabilities
originate in third-party components, and those flaws take an average of 358 days to fix – 115 days longer than vulnerabilities found through other scan types.

AI-Generated Code Is Failing Security Tests at Scale

In 85% of tests, AI-generated code failed security checks for cross-site scripting – a vulnerability class that can expose citizen data, financial records, and mission-critical systems in public-facing web applications.

The information provided in this document is for general informational and educational purposes only. It does not constitute legal advice, and should not be relied upon as legal advice. Regulatory and compliance requirements vary by organization, jurisdiction, and context. Organizations should consult qualified legal counsel and compliance professionals to understand and address their specific regulatory obligations. Veracode makes no representations or warranties regarding the completeness, accuracy, or applicability of the information contained in this document. Regulatory frameworks discussed in this article are subject to change; readers should consult the official regulatory bodies and legal resources for the most current requirements.