Skip to content

Written by AI.How we work

Product1 publisherNot yet confirmed elsewhere3 min readPublished

HackerOne's data shows open vulnerability backlogs outrunning a halved time-to-fix

HackerOne says companies cut average vulnerability fix time from 135 days to 62, yet validated findings left unresolved rose 131% over two years. That leaves time-to-fix a poor guide to exposure, and paying the debt down means taking capacity away from feature work.

The Product Desk · Product desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying HackerOne's data shows open vulnerability backlogs outrunning a halved time-to-fix
Generated illustration

What happened

  • In a separate HackerOne survey of 111 security leaders, 70% said validated findings are being added to their backlogs faster than they are being remediated.
  • Of 408 security researchers HackerOne surveyed, 85% said they are actively upskilling with AI, and nearly three-quarters reported a meaningful rise in valid findings.
  • As developers write more code with AI, HackerOne logged a 557% rise in system prompt leakage reports and a 264% rise in output handling reports.
  • Kara Sprague, HackerOne's chief executive, said exposure debt is higher than at any point in the ten years the company has published application security reports.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • decision Security leads will need to report the open-findings trend ahead of time-to-fix, because only the open count reflects what is still exploitable.
  • exposure If exploits can be built within hours of disclosure, as devops.com reports, even the improved average leaves known flaws open for weeks after an attack becomes possible.
  • cost Reserving engineering time for security debt is paid in delayed features, so product owners share the cost of any serious paydown plan.

The slide a security lead takes into the quarterly review tends to open on time-to-fix, because it is the figure that improved. In HackerOne's report, the claim that resolution got 54% faster in a year [2] is the same percentage as the cut in average resolution time [16]. Both describe how long a finding waited before someone closed it. The count of validated findings still open is a separate figure, and it now stands at 2.31 times its level of two years ago [17].

Teams tell themselves that a falling time-to-fix means falling exposure. The queue behaves differently. An average resolution time is calculated on findings that got resolved, so it can improve every quarter while older items sit. When findings arrive faster than they close, the open count climbs no matter how quick each closure is.

It helps to know who is counting. HackerOne publishes the backlog figures and also runs the platform where much of the discovery is paid for. Organizations on it awarded researchers a record $89 million between July 2025 and June 2026, up 18% on the prior year [11], or roughly $14 million more [18]. Its researcher survey found 68% have moved toward higher-complexity, higher-bounty bugs with AI's help [10]. The company's remedy, as CEO Kara Sprague described it, is for DevSecOps teams to apply AI to remediation and formalize vulnerability operations practices [5]. The devops.com write-up says it is not clear how fast teams are adopting AI to reduce exposure debt [15].

Sprague's more useful point concerns budget. Far too many organizations still put a much higher share of application development effort into new applications and features than into reducing security debt, she said [12]. Three-quarters of surveyed security leaders say their organization formally tracks exposure debt [8]. The survey, as reported, does not say how many of them reserve engineering time to reduce it.

The case for moving those hours has a weak spot. Discovery has clearly risen, but devops.com says it is not clear breaches have risen with it [14]. A budget request built on incident counts will be thin. One built on the open-count trend has HackerOne's own numbers behind it [3].

I'd sort the decision on two axes. One is whether findings closed faster than they arrived last quarter. The other is whether exposure debt has a capacity reservation that the owner of the feature roadmap signed.

Closing faster with a reservation: time-to-fix is an honest headline metric, and the team can keep leading with it. Closing faster without one: the team is betting that discovery holds steady, against a researcher survey that points the other way [9]. Arriving faster with a reservation: the reservation is too small, and the argument for raising it should rest on the open count. Arriving faster without one: a better time-to-fix mostly reports how hard the team is working.

I'd size the reservation to close more findings than arrive each quarter. The tradeoff sits in the same hours: whatever is reserved comes off the roadmap, so the roadmap owner has to agree to the number in writing, alongside the security lead [12].

What to watch

  • Whether HackerOne's next report gives findings closed per quarter next to findings opened, so throughput can be checked directly.
  • Breach data showing whether the rise in discovered vulnerabilities is turning into more incidents.
  • Results from teams applying AI to remediation, measured by open counts falling as well as by time-to-fix.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories