Veracode Reveals Half of Organizations Burdened by Critical Security Debt, with 70% Stemming from Third-party Code and the Software Supply Chain
Veracode, a global leader in application risk management, today launched its 15th edition of the State of Software Security (SoSS) report. The report, based on an extensive dataset of 1.3 million unique applications and 126.4 million raw findings, highlights important trends and offers a new view of software security maturity to improve application risk management practices.
This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250227022178/en/
Percentage of Security Debt Across Organizations (Graphic: Business Wire)
The research reveals an alarming increase in the average fix time for security flaws—from 171 days to 252 days over the past five years, and up 327 percent since the report’s first volume 15 years ago. Moreover, 50 percent of organizations now carry critical security debt, defined as accumulated flaws left open for longer than a year. The majority of these vulnerabilities originate from third-party code and the software supply chain. Unresolved security debt leaves organizations open to attack, exposing them to reputational, financial, and operational damage.
Chris Wysopal, Chief Security Evangelist at Veracode, said, “The attack surface has become increasingly complicated, particularly in the last couple of years with the explosion of AI engineering. Last year’s report found 46 percent of organizations had high-severity security debt. While the year-on-year increase may seem marginal, it is going in the wrong direction. Our investigations provide solid evidence that organizations can drive down debt, but many need help to prioritize which vulnerabilities to tackle first.”
Benchmarking Security Performance
Veracode’s research also analyzed the distribution of security debt across organizations. While some have almost no debt and others are drowning in it, most fall somewhere in between, with a mix of debt-free and debt-ridden applications.
“The gap between the top 25 percent and bottom 25 percent of organizations is fascinating,” Wysopal said. “The results raise the question of which factors account for the marked differences in how organizations manage security debt and what teams can do to tackle it.”
Veracode’s research pinpoints five key metrics that indicate security maturity and predict an organization’s ability to systematically reduce risk: flaw prevalence, fix capacity, fix speed, debt prevalence, and open-source debt. The report explains each metric’s importance and reveals the parameters that determine whether an organization is “leading” or “lagging.”
- Flaw prevalence: Leading organizations have flaws in fewer than 43 percent of applications, while lagging organizations exceed 86 percent.
- Fix capacity: Leaders resolve over 10 percent of flaws monthly, whereas laggards address less than 1 percent.
- Fix speed: Top performers remediate half of flaws in five weeks; lower-performing organizations take longer than a year.
- Security debt prevalence: Less than 17 percent of applications in leading organizations carry security debt, compared with more than 67 percent in lagging ones.
- Open-source debt: Leading organizations keep open-source critical debt under 15 percent, while 100 percent of critical debt is open source in lagging organizations.
Wysopal said, “The research provides a helpful framework for organizations to assess their security maturity. This enables them to understand specific factors contributing to security debt, gauge each metric’s importance, and benchmark their own performance against similar organizations. We offer in-depth recommendations from our experts and leading organizations on how to improve.”
Cyber Regulations Drive Positive Behaviors, Boosting Application Security
On a positive note, Veracode’s research found the rate of applications passing the Open Worldwide Application Security Project (OWASP) Top 10 has increased by 63 percent over the past five years, and more than doubled in 15 years. New cybersecurity regulations in 2024, like the U.S. Securities and Exchange Commission (SEC) ruling and E.U. Cyber Resilience Act, have contributed to this trend as software vendors take a more disciplined approach to risk management.
A New View of Security Maturity
Veracode’s new view of software security maturity emphasizes the need for enterprises to take a strategic, context-driven approach to managing the most urgent and exploitable risks. The report recommends two key focus areas for organizations. First, organizations must enhance visibility and integration across the entire software development life cycle, using automation and feedback loops to prevent new security flaws. Second, they should prioritize correlating and contextualizing security findings in a single view, allowing them to efficiently address their security backlog and reduce the highest risks with the least effort.
Wysopal added, “Tools like Application Security Posture Management enable security professionals and development teams to prioritize and make informed decisions by pinpointing what’s exploitable, reachable, and urgent.”
As organizations navigate an increasingly complex threat landscape, prioritizing security maturity is essential. Veracode’s research provides a roadmap for organizations to benchmark and improve their security posture. By addressing security debt and leveraging the best tools and practices, businesses can enhance resilience, reduce risk, and comply with evolving cybersecurity regulations.
The full State of Software Security 2025 report is available to download on the Veracode website. A blog outlining the key findings from the report is also available to read.
About the State of Software Security Report
The Veracode State of Software Security 2025 is the 15th volume of the report. It analyzed data from companies of all sizes, commercial software suppliers, software outsourcers, and open-source projects. The report contains findings about applications that were subjected to static analysis, dynamic analysis, software composition analysis, and/or manual penetration testing through Veracode’s cloud-based platform. Specifically, the data comes from:
- 1.3M unique applications with 126.4M raw findings
- 107.4M findings identified via SAST scans
- 3.9M findings identified via DAST scans
- 15M findings identified via Software Composition Analysis
About Veracode
Veracode is a global leader in Application Risk Management for the AI era. Powered by trillions of lines of code scans and a proprietary AI-assisted remediation engine, the Veracode platform offers adaptive software security and is trusted by organizations worldwide to build and maintain secure software from code creation to cloud deployment. Thousands of the world’s leading development and security teams use Veracode every second of every day to get accurate, actionable visibility of exploitable risk, achieve real-time vulnerability remediation, and reduce their security debt at scale. Veracode is a multi-award-winning company offering capabilities to secure the entire software development life cycle, including Veracode Fix, Static Analysis, Dynamic Analysis, Software Composition Analysis, Container Security, Application Security Posture Management, Malicious Package Detection, and Penetration Testing.
Learn more at www.veracode.com, on the Veracode blog, and on LinkedIn and X.
Copyright © 2025 Veracode, Inc. All rights reserved. Veracode is a registered trademark of Veracode, Inc. in the United States and may be registered in certain other jurisdictions. All other product names, brands or logos belong to their respective holders. All other trademarks cited herein are property of their respective owners.
View source version on businesswire.com: https://www.businesswire.com/news/home/20250227022178/en/
Contacts
For more information, please contact:
Katy Gwilliam
kgwilliam@veracode.com
About Business Wire
For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.
www.businesswire.com

Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
Skechers AERO Series Opens New Chapter of Technical Running Innovation16.7.2025 10:00:00 EEST | Press release
Skechers Performance opens a new chapter of running innovation with the arrival of the Skechers AERO series. Named for the aerodynamic feel of the design, Skechers AERO represents the latest evolution of technical running shoes from the brand. The collection is engineered to deliver an exhilarating blend of speed, style and comfort to help runners cut through the wind and push beyond their personal bests while logging miles. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250716754749/en/ Introducing the Skechers AERO Series of technical running shoes: Skechers AERO Burst, Skechers AERO Spark, and Skechers AERO Tempo (L-R). “Recently launched in North America and Asia, the AERO Series leverages innovative technologies to elevate our signature comfort that’s now available to runners in Europe,” said Ben Stewart, Vice President, Skechers Technical Performance Division. “An evolution of our legacy in running, Skechers AERO was d
The Future of Connectivity Starts Here: Network X Returns to Paris October 14 - 1616.7.2025 10:00:00 EEST | Press release
Network X 2025 - the only event that brings the fixed and mobile markets together - returns to Paris Expo Porte de Versailles October 14 - 16. Built for telecom's top players, this annual show drives business model innovation and monetisation of next-generation fixed, mobile, satellite and transport networks through AI and cloud. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250716595903/en/ Speaker on Headliners Stage at Network X 2024 New to Network X in 2025 are specialty events designed to deliver expert insights on trending topics including Data Center World and two Expo Stages for Fixed-Line and Mobile. More than 5,500 telco network infrastructure professionals will gather alongside 1,500 telcos to learn from six program tracks highlighting the latest advancements in Fibre, Wi-Fi Networks and Services, IP and Optical Transport, Mobile Networks, Mobile Services, and Data Centres. “Network X is more than a conference—it
4Moving Biotech Enrolls First Patient in Phase 2a Trial of 4P004, a Potential First-in-Class GLP-1 Therapy for Knee Osteoarthritis16.7.2025 08:00:00 EEST | Press release
4Moving Biotech (4MB), a spin-off of 4P-Pharma dedicated to developing first-in-class treatments that modify the natural course of knee osteoarthritis (OA), today announced that the first patient has been enrolled in Phase 2a clinical trial, INFLAM MOTION. The study will evaluate 4P004, an intra-articular GLP-1 analog, as a potential first-in-class therapeutic candidate for knee osteoarthritis. INFLAM MOTION is a multicenter, randomized, double-blind, placebo-controlled Phase 2a trial planned to be conducted across Europe, the United States, and Canada. A total of 129 patients worldwide diagnosed with knee OA will be enrolled to evaluate, for the first time in humans, the efficacy of 4P004. “Enrolling our first patient is a pivotal step toward rewriting the treatment paradigm for knee osteoarthritis,” said Professor Francis Berenbaum, MD, PhD, Chief Medical Officer at 4Moving Biotech. “Almost 600 million people live with OA, yet no disease-modifying therapy has been done to patients. B
Belkin Achieves Qi2.2 Certification for Its Upcoming Products, Unlocking the Future of 25W Wireless Charging15.7.2025 20:06:00 EEST | Press release
Belkin, a leading consumer electronics brand for over 40 years, today announced it has received official Qi2.2 certification from the Wireless Power Consortium (WPC) for its upcoming products. As one of the first accessory brands to deliver Qi2.2-certified devices, Belkin is helping bring the next generation of wireless charging to market – enabling faster wireless charging speeds, broader compatibility, and improved performance for consumers. Belkin’s close partnership with the WPC since 2015 has been instrumental in bringing these advancements to consumers. As an early adopter and long-time contributor to WPC standards, Belkin was selected as one of a small group of trusted manufacturers to test and certify Qi2.2 products ahead of the broader industry rollout. All Belkin products undergo rigorous safety, quality, and performance testing. The company’s global headquarters includes WPC certified test equipment and state-of-the-art test labs dedicated to full product lifecycle validatio
Cessna Grand Caravan EX to Feature New Executive Interior Options, Expanding Opportunities for Elevated Missions15.7.2025 19:05:00 EEST | Press release
The legendary Cessna Grand Caravan EX will now feature three new executive interior schemes for customers to select when designing their aircraft cabin. The Lunar, Obsidian and Saddle Sport interiors join the existing Canyon and Savanna schemes, providing a broader range of standard choices. The new interior options are available to customers starting this month and allow them to further tailor the interior of their aircraft based on their personal preference or mission. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250715021096/en/ Cessna Grand Caravan EX to feature new executive interior options, expanding opportunities for elevated missions (Photo Credit: Textron Aviation) The Cessna Grand Caravan EX is designed and manufactured by Textron Aviation Inc., a Textron Inc. (NYSE:TXT) company. Premium versions of each of the new interiors are also available, featuring quilted seat stitching and plush carpet, providing an elev
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom