Contrast Security, the leader in runtime application security, today released AppSec Overflow 2026, a research report showing that the find-and-fix workflow underpinning modern application security no longer holds up against AI-accelerated attackers and AI-powered security assessments.
Drawing on runtime telemetry from inside hundreds of thousands of production applications and APIs worldwide, the report shows the growing pressure defenders face at the application layer. Attackers touch the average application 11,382 times per month, roughly once every four minutes. Of those, an average of 42 monthly attacks are viable, meaning exploitation attempts are confirmed to have reached and triggered real vulnerable code.
At the same time, AI is making it faster and easier for attackers to find and exploit vulnerabilities. Attackers have always used automated scanning, but AI lets them find and weaponize vulnerabilities with less skill than ever.
"AI is not going to triage its way out of this problem, and we have the data to prove it," said David Lindner, Chief Information Security Officer at Contrast Security. "These tools disagree with each other; they disagree with themselves from one run to the next, and none of them can tell me how my application behaves when someone is actually attacking it."
"For twenty years the discipline of AppSec has been organized around a race: find the vulnerability, decide if it matters, and fix it before somebody with bad intent finds it first," said Jeff Williams, Founder and CTO at Contrast Security, "AI ended that race, and defenders lost it. We are now seeing vulnerabilities weaponized in hours while the average critical fix takes weeks or months."
Key findings include attackers reaching real vulnerabilities every day with untrusted deserialization leading by volume followed by path traversal and method tampering and SQL injection in top five for every industry. The attack surface is expanding faster than defenders can keep up with 106 vulnerability findings average. In third-party code 54% of CVE instances come from CVEs published more than a year ago. AI is making this worse as much as better with scanners agreeing only 5% and self-reproducing 17%.
AppSec Overflow 2026 concludes that finding, prioritizing, and remediating remains necessary but is no longer sufficient on its own. No remediation cadence matches the velocity at which AI-assisted attackers identify and exploit weaknesses, and no review process keeps pace with AI-assisted code generation without slowing development.
The report makes the case for moving more of the defense inside the application, where runtime visibility allows teams to see attacks as they happen and block them in real time. That means vulnerabilities can be protected before they are patched, whether they are newly discovered, still unknown or introduced by AI-generated code. Findings are drawn from anonymized aggregate telemetry collected from thousands of live applications spanning trillions of observations per day via lightweight sensor observing control flow, data flow and backend interactions.
About Contrast Security
Contrast Security is the global leader in Application Detection and Response (ADR), empowering organizations to see and stop attacks on applications and APIs in real time. Contrast embeds patented threat sensors directly into the software, delivering unmatched visibility and protection. With continuous defense, Contrast uncovers hidden application-layer risks that traditional solutions miss. Contrast's powerful Runtime Security technology equips developers, AppSec teams and SecOps with one platform that proactively protects and defends applications and APIs against evolving threats.