The 2026 State of Software Security (SoSS) report illuminates a difficult truth: the pace of flaw creation is decisively outstripping the current capacity for remediation. Despite marginal gains in fix rates, the tide of security debt – known vulnerabilities left unresolved for more than a year – is rising. This is not a distant problem; it is a present reality for 82% of organizations, an 11% increase in a single year. Plus, the debt accumulating is not benign. Critical security debt (flaws that are both severe and highly exploitable) now affects 60% of organizations, a stark 20% rise from the previous year, and high-risk vulnerabilities saw a 36% relative increase.
Read the full report by clicking on the download button below.
