Key Insights:

Critical Security Debt Is Up 20% in One Year
The most weaponizable flaws – highly severe, highly exploitable, unresolved for over a year – now affect 60% of organizations, giving nation-state actors and ransomware groups a larger and more dangerous attack surface than a year ago.

Third-Party Code Is Where the Worst Debt Lives
66% of the most dangerous, longest-lived vulnerabilities
originate in third-party components, and those flaws take an average of 358 days to fix – 115 days longer than vulnerabilities found through other scan types.
AI-Generated Code Is Failing Security Tests at Scale
In 85% of tests, AI-generated code failed security checks for cross-site scripting – a vulnerability class that can expose citizen data, financial records, and mission-critical systems in public-facing web applications.
The information provided in this document is for general informational and educational purposes only. It does not constitute legal advice, and should not be relied upon as legal advice. Regulatory and compliance requirements vary by organization, jurisdiction, and context. Organizations should consult qualified legal counsel and compliance professionals to understand and address their specific regulatory obligations. Veracode makes no representations or warranties regarding the completeness, accuracy, or applicability of the information contained in this document. Regulatory frameworks discussed in this article are subject to change; readers should consult the official regulatory bodies and legal resources for the most current requirements.