Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Software security debt is widespread in the applications measured by Veracode, and serious vulnerabilities are taking longer to clear—especially in third-party components. That points to a growing vulnerability-management burden, not a proven forecast of more breaches: the available figures measure vulnerability findings, forecasts of future disclosures, and a UK survey of reported incident outcomes, not a single global breach trend.

What security debt means—and what the figures measure

Security debt is accumulated security risk left unresolved as software and systems age. In its 2026 State of Software Security, Cyentia Institute uses a narrower, measurable definition: known vulnerabilities that have remained unresolved for more than a year. Its statistics come from analysis of Veracode cloud-platform data, not a representative census of every company.

Using that definition, Cyentia reports that 82% of organizations in the analyzed data had security debt. It also reports that 60% carried critical security debt, up 20% year over year, while the concentration of high-risk vulnerabilities rose 36% year over year. These are different measures: the first concerns the share with old findings, the second the share with critical debt, and the third the concentration of high-risk vulnerabilities. They indicate a serious backlog in this dataset, but should not be read as prevalence estimates for all businesses.

Why old and third-party vulnerabilities are difficult to clear

Age matters because a finding that stays unresolved for more than a year can signal more than a short-lived patch queue. It may reflect dependencies that are hard to update, unclear ownership, compatibility concerns, or insufficient capacity. The data establish the age of findings, not the reason any particular organization failed to fix them.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Third-party software is a substantial part of the reported critical debt. Cyentia attributes 66% of critical security-debt vulnerabilities to third-party components. Its reported half-life for third-party flaws is 358 days, compared with 243 days across all scan types. A half-life describes the time for half of the observed flaws to be fixed; it is not a promise that a given vulnerability will be resolved on that schedule.

Cyentia also says median organizations fix about 10% of their total vulnerability backlog each month, a report-specific rate it characterizes as insufficient to keep pace with flaw creation. That figure is not a universal remediation benchmark, and the underlying backlog can include findings with very different levels of risk.

More vulnerability disclosures mean more triage—not a breach forecast

FIRST’s 2026 forecast concerns Common Vulnerabilities and Exposures (CVEs) expected to be disclosed, not vulnerabilities successfully exploited and not the number of breaches. Its median forecast is 59,427 CVEs for 2026, with a 90% interval from 30,012 to 117,673. The median forecasts are 51,018 for 2027 and 53,289 for 2028.

Year FIRST median CVE forecast Forecast interval
2026 59,427 30,012–117,673 (90% interval)
2027 51,018 Not stated in the cited release
2028 53,289 Not stated in the cited release

The practical implication is workload: security teams need ways to identify which new disclosures affect their software and which findings deserve attention first. As Éireann Leverett, FIRST Liaison and Lead Member of FIRST’s Vulnerability Forecasting Team, put it: “The question organizations need to ask right now is: are my people and processes ready to handle this volume, and am I prioritizing the vulnerabilities that actually put my data at risk?” The forecast supports planning for vulnerability intake and prioritization; it does not establish that breach counts will rise.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What the breach evidence does—and does not—show

The UK Department for Science, Innovation and Technology’s 2025/2026 Cyber security breaches survey found increases in the shares of UK businesses reporting certain impacts after an incident compared with its 2024/2025 survey. The survey is geographically limited and relies on reported experiences; its figures should not be generalized to businesses worldwide.

Reported impact among UK businesses 2024/2025 2025/2026
Revenue or share-value loss after an incident 2% 5%
Reputational damage after an incident 1% 3%

At the same time, the survey’s median perceived cost for the most disruptive breach or attack was £0 for businesses overall and £30 for medium and large businesses. These are medians of respondents’ perceived costs, not estimates of the total economic impact of cyber incidents. The combination cautions against turning selected increases in reported impacts into a simple claim that breaches are becoming more frequent or more costly everywhere.

Security debt is also a governance and capacity problem

ISACA’s broader discussion treats security debt as more than a list of old scanner findings. It includes outdated systems, deferred remediation, unpatched vulnerabilities, and underresourced programs, with contributing factors across technology, people, culture, and governance. That framing matters because a team cannot reduce a backlog sustainably if no one owns remediation, upgrades repeatedly lose priority, or the organization lacks a way to judge risk against business impact. Unmanaged debt can threaten confidentiality, integrity, availability, compliance, and trust.

Separate industry reports add context but use different measures. Software Improvement Group’s State of Software 2026, based on benchmark data across tens of thousands of systems, reports that 71% of code had a low degree of security controls and that an average-sized system contained 20 critical security findings. It also reports roughly twice the security-risk violations in AI-generated code compared with human-written code. These measures are not equivalent to Cyentia’s count of vulnerabilities older than a year, so they should not be combined into one estimate of security debt.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The World Economic Forum’s Global Cybersecurity Outlook 2026 reports that 87% of survey respondents identified AI-related vulnerabilities as the fastest-growing cyber risk over 2025. It also says the share of organizations assessing the security of their AI tools rose from 37% in 2025 to 64% in 2026. These are reported perceptions and practices, not evidence that AI caused a particular breach or drove the overall security-debt trend.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How organizations can prioritize remediation

A large finding count is not, by itself, a useful order of work. A practical program needs to connect vulnerability data to the systems, dependencies, and business processes affected, then give teams a clear route from identification to verified remediation.

  1. Establish what is in scope. Map applications and services to their owners, deployed versions, environments, and software dependencies. Include direct and transitive third-party components where the available tooling supports them.
  2. Separate risk from volume. Triage by severity and exploitability, exposure of the affected system, and the data or business function at stake. Use raw CVE totals as workload context rather than treating every disclosure as equally urgent.
  3. Make age visible. Track newly identified issues separately from findings that have remained unresolved for a year or longer. Review overdue items for blockers, ownership, and an agreed remediation or mitigation path.
  4. Assign responsibility across the supply chain. For third-party findings, identify which internal service depends on the component, who can update it, and whether a safe version or mitigation is available. A component’s presence in a dependency tree does not alone establish that an affected code path is reachable or exposed.
  5. Verify closure and revisit priorities. Record the fix or mitigation, confirm the finding no longer applies in the deployed software, and reassess when exposure or business context changes. Feed recurring delays into planning, staffing, and governance rather than allowing them to become invisible backlog.

Software composition analysis, application security testing, dependency vulnerability management, and risk-based prioritization can support this work. When assessing any tool or service, check its coverage of direct and transitive dependencies, exploitability context, integration with existing development and ticketing workflows, and ability to track remediation through verification. No single finding count or scan result substitutes for accountable ownership and decisions based on the system’s actual exposure.

What the data supports about the outlook

The evidence supports concern about a persistent, high-risk vulnerability workload: the Cyentia analysis finds widespread old vulnerabilities and rising critical debt in Veracode data, while FIRST anticipates substantial CVE disclosure volumes that require triage. The UK survey records increases in some reported business impacts, but its median perceived cost remains low and its findings apply to UK respondents. Taken together, these sources raise concern about exposure and the capacity to manage it; they do not establish a global increase in breach frequency or predict future breach counts.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.