
SamHouston (Veracode) asked a question.
FYI - Our new 2025 State of Software Security (SOSS) report is now available for download: https://www.veracode.com/resources/analyst-reports/state-of-software-security-2025/
Software Security Debt is Growing:
The average time to fix flaws has increased 47% in 5 years, now averaging 252 days.
3rd Party and Open-Source Risks are Increasing:
70% of critical security debt comes from third-party code and software supply chain issues.
AI-Generated Code is Increasing:
AI-generated code is increasing, but many teams lack visibility into its security risks.
High-Severity Flaws are Common:
The percentage of applications with high-severity flaws has increased by 181%.
Top Orgs Find & Fix Fast:
Leading organizations fix half of flaws in 5 weeks, while lagging companies take over a year.
.png)