Security1 distinct publisher3 min readPublished
Contrast's 2026 production telemetry says the average application absorbs dozens of exploit attempts that actually fire each month, while its own bench test found three AI scanners barely agree on what to fix first.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Cross-tool disagreement wasn't even the harder problem in that test. The internal number was worse: one scanner run three times against identical code reproduced only 17 percent of its own findings [7], meaning the same tool on the same commit came back with a different queue each time. A list a team cannot reproduce is a list it cannot burn down or audit.
The economics point the same way. Contrast puts the API cost of scanning a 2-million-line codebase at roughly $315 [8] and the cost of triaging what came back at about $128,000 [9]. That is a ratio of about 406 to 1 [1]. Generation costs about what compute costs; adjudication costs about what people cost.
Which is why the exploit telemetry carries more weight than the finding counts. Forty-two confirmed viable attempts a month against 3.4 closures works out to roughly twelve triggered exploit attempts for every vulnerability a team retires [4]. Untrusted deserialization led those confirmed exploits, followed by path traversal and method tampering [4], and SQL injection sat in the top five techniques across every vertical Contrast tracked [5]. Log4Shell and Spring4Shell are both still visible in production telemetry [13]. At the observed closure rate, an average 106-finding backlog is about 31 months of work, and the high and critical findings alone are about six and a half months if nothing else gets touched [2][3]. The average highest-severity fix takes 92 days [12].
The attack-volume figure needs reading carefully. One adversary touch every four minutes [2] is roughly 10,800 events per application per month [5], but Contrast also reports that more than 60 percent of applications see fewer than 3,000 attacks a month while more than a quarter absorb 30,000 or more [20]. The mean describes the top quartile, not the median application.
Scores narrow the field without settling it. Contrast found 82 percent of the CISA KEV entries in its dataset carried an EPSS score of 90 percent or higher [18], which is a usable filter. Two entries, CVE-2006-1547 and CVE-2023-38180, each carried CVSS 7.5 with EPSS under 25 percent, and both were confirmed exploited in the wild [19].
The supply side is moving in the same direction. Zero Day Clock, drawing on more than 83,000 CVEs, put mean time to exploit above two years in 2018, below one year by 2021, and found the majority of vulnerabilities exploited in 2025 were weaponized within three weeks [16]. Thirteen weeks to fix the worst class against three weeks to weaponize is a gap of about four to one [6]. HackerOne paused new submissions to the Internet Bug Bounty in March 2026, and Node.js paused its own program shortly after, citing the loss of that funding [17].
One caveat, stated plainly: this is vendor telemetry. Contrast CISO David Lindner's framing is that these tools disagree with each other, disagree with themselves between runs, and cannot describe how an application behaves while someone is attacking it [14], and that argument favours the in-production vantage point Contrast measures from [1]. The 17 percent reproducibility figure is the part any team can check on its own code, at the price of one rerun.
Ranked by verification strength, evidence, and original report placement.
Contrast Security's AppSec Overflow 2026 report draws on telemetry collected from inside hundreds of thousands of production applications and APIs.
Adversaries touch the average application once every four minutes, most of that traffic being automated reconnaissance mapping weaknesses and cataloguing services.
Contrast recorded 42 confirmed, viable exploit attempts per application every month, meaning the vulnerability was not just probed but triggered.
Zero Day Clock, which aggregates exploit signals from more than 83,000 CVEs, recorded a mean time to exploit of more than two years in 2018, below one year by 2021, and found the majority of vulnerabilities exploited in 2025 were weaponized within three weeks.
More than 60 percent of applications see fewer than 3,000 attacks per month, and more than a quarter absorb upward of 30,000 attacks per month.
Untrusted deserialization led the field among confirmed exploits, followed by path traversal and method tampering.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 30, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
Frontier AI can find the bugs faster. The patch queue is the number nobody published.1 distinct publisher
security
The disclosure pipeline is triaging itself: 20,700 new CVEs, 10% more exploitation1 distinct publisher
build
8,900 hostile requests, none of them dangerous: reading a Next.js site's own edge log1 distinct publisher
security
A CVSS 10.0 RCE in Entra ID was exploited in the wild, and there was nothing to patch1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One vendor report, one outlet
Follow any number in this story back and you arrive at the same door: Contrast Security's report, relayed by Help Net Security with no second voice in the room. The telemetry base is stated as hundreds of thousands of production applications, but the sampling, the criteria for calling an exploit attempt 'viable', and the identity of the three AI scanners are all missing. The only assertions a reader could verify elsewhere — the Internet Bug Bounty and Node.js pauses — are not the ones doing the work.
Wide agent footprint, bench-test headline
Two different things are being counted here and only one is adoption. Contrast is genuinely reading its own agents across a large production estate, which is what gives the attack and backlog numbers their weight. The AI-scanner finding is not adoption at all — one internal run against one codebase, no named tools, no users. And the only field events on offer, HackerOne halting Internet Bug Bounty submissions and Node.js following, describe funding retreating rather than anything being taken up.
Headline outruns the test
The 95 percent disagreement line is arithmetic on a 5 percent agreement rate from a test the vendor designed, ran once, and did not document — stated with far more force than that supports. 'Every four minutes' is a mean the report's own distribution quietly undercuts, since most applications take fewer than 3,000 attacks a month while the top quarter absorbs over 30,000. The irony is that the least promoted number is the most solid: 106 findings against 3.4 closures a month is 31 months of queue, and it needs no interpretation whatsoever.
Findings favour the publisher's product
Contrast's CISO says the tools cannot tell him how an application behaves while it is being attacked — which is a description of runtime monitoring, the thing Contrast sells. Both quotes in the story are Contrast executives; the corroborating exploit-timing series is credited to Zero Day Clock with no word on who runs it; no scanner vendor is asked to respond. None of that makes the figures wrong, but nobody holding an opposing interest touched them before publication.
Clear sourcing, unverifiable numbers
What can be judged, we judge cleanly: this is one outlet summarizing one interested party, and that shape is not in question. What cannot be judged from here is whether the underlying telemetry and the bench test are sound — a second account, or the report's methodology, would move this reading further than any further reading of what we have.