State of Application Security

Cyber

October 5, 2026

State of Application Security

Our View from the Front Lines of Technical Assessments

Kroll analyzed five years of penetration testing data. Of the trends that emerged, we focus on three in this report: the static application security testing (SAST)/software composition analysis (SCA) plateau, the need for more attention around authentication and authorization, and the security health divergence, which shows that regulation is not a reliable predictor of attack surface health.

 

In the report

  • Foreword from Krish Raja, Managing Director, Global Head of Offensive Security
  • Key Insights
  • Section 1—The Three Trends We’re Seeing
  • Section 2—The Data: Slicing the Vulnerability Landscape
  • Section 3—Looking Ahead
  • About the Firm

Key Insights

 

The SAST/SCA Plateau

Modern SAST/SCA tools remain foundational security controls. Organizations that have not yet implemented them still have significant opportunities for risk reduction. However, among organizations already operating mature shift-left programs, designed to move testing earlier in the software development life cycle (SDLC), our data indicates that the security gains available through additional investment in the same tooling category are becoming limited. The industry’s remaining risk is concentrating in places that automated scanning cannot easily reach at this time.

 

Authentication and Authorization Deserve More Attention

The most serious vulnerabilities in modern applications are not primarily injection flaws, dependency issues or configuration mistakes; they are authentication and authorization vulnerabilities. Broken Access Control issues alone account for more than 40% of all critical- and high-severity findings in the dataset. When this category is combined with the Identification and Authentication Failures category, these issues represent nearly 60% of the serious vulnerabilities that were observed. These issues are also the least detectable through static analysis and are disproportionately introduced during the design phase of software development.

 

The Security Health Divergence: Regulation Doesn’t Dictate Security

Over the observation period, some sectors demonstrated measurable improvements in vulnerability density, severity and overall attack surface health. Others remained stagnant or declined despite operating under similar regulatory pressures.

One discovery stands out: Regulation is not a reliable predictor of better outcomes. Two heavily regulated industries in our dataset followed markedly different security trajectories despite sharing comparable compliance obligations.

Looking Ahead: What the Next 12–24 Months Look Like

The next 12–24 months will bring meaningful changes to the world of offensive security, particularly within the sphere of application security assessments. AI is likely the most consequential vector regarding both how software is written and how it is analyzed. Other emerging areas warrant attention as well.

 

AI and Large Language Models (LLMs) in Application Security

  • AI-enhanced SAST/SCA Tooling: Current static tooling has a plateau. It does what it is designed to do but does not extend into identifying design-stage, authorization or authentication findings. Whether AI/LLM-enriched static analysis can reach previously unreachable finding classes is one of the more interesting open questions. If it can, the SAST/SCA plateau argument may look different in future editions of this report.
  • AI-assisted Coding Upstream: ChatGPT debuted in late 2022. AI-assisted coding tools have reached wide adoption since then. As AI-generated code becomes more prevalent in production applications, the vulnerability profile that penetration tests observe will likely shift in severity, detectability, sophistication or some combination of all these factors. Our current data does not yet show a distinct signal attributable to this trend, but we may be able to reflect these shifts in the future.  

 

Other Emerging Areas

  • Evolving Mobile Threat Landscape: Our study pools web and mobile findings together, but we could look to split these application types in the future.
  • Supply Chain and Third-party Component Risk: This risk is connected with the observations made in §2.5 regarding the diminished but not eliminated presence of memory safety issues and in §2.6 regarding the Vulnerable and Outdated Components category. The economic pressure on transitive dependency risk is likely to grow.

Read more about Kroll’s Threat Exposure Management services and explore a recent case study on AI-assisted penetration testing, demonstrating how AI-accelerated testing, guided by human expertise, helped a large financial institution understand its Frontier AI vulnerability.

Stay Ahead with Kroll

Threat Exposure Management

Kroll’s field-proven cyber security assessment and testing solutions help identify, evaluate and prioritize risks to people, data, operations and technologies worldwide.

Penetration Testing Services

Validate your cyber defenses against real-world threats.

Regulatory Compliance Assessments

Expert support to comply with a wide range of cybersecurity compliance requirements and build long-term cyber resilience.

Cyber Risk Assessments

Kroll's cyber risk assessments and advisory services deliver actionable recommendations to improve security, using industry best practices & the best technology available.

Cloud Security Services

Kroll’s multi-layered approach to cloud security consulting services merges our industry-leading team of AWS and Azure-certified architects, cloud security experts and unrivalled incident expertise.

AI Security Testing Services

Kroll’s offensive security experts test artificial intelligence (AI), large language model (LLM) and machine learning (ML) technologies to enable systems to follow fundamental security principles and reduce risk to organizations.

Threat-Led Penetration Testing

Simulate real-world attacks, uncover vulnerabilities, and strengthen your defenses in line with DORA requirements with guidance from Kroll's offensive security experts.

API Penetration Testing Services

Kroll’s certified pen testers find vulnerabilities in your APIs that scanners simply can’t identify. Protect your business and keep sensitive data secure by leveraging our knowledge and experience in testing modern API infrastructures.

Cloud Penetration Testing Services

Kroll’s team of certified cloud pen testers uncover vulnerabilities in your cloud environment and apps before they can be compromised by threat actors.

Web Application Penetration Testing Services

Assess the design, configuration and implementation of your web apps for critical vulnerabilities. Kroll’s scalable pen testing services consider the business case and logic of your apps, providing more coverage and an optimized program based on risk.