Contrast Security, the leader in runtime application security, released AppSec Overflow 2026, a research report showing that the find-and-fix workflow underpinning modern application security no longer holds up against AI-accelerated attackers and AI-powered security assessments.
Drawing on runtime telemetry from inside hundreds of thousands of production applications and APIs worldwide, the report shows the growing pressure defenders face at the application layer. Attackers touch the average application 11,382 times per month, roughly once every four minutes. Of those, an average of 42 monthly attacks are viable, meaning exploitation attempts are confirmed to have reached and triggered real vulnerable code. For an enterprise running hundreds of applications, that means thousands of confirmed exploitation attempts every month, each one a real attack against a real weakness.
At the same time, AI is making it faster and easier for attackers to find and exploit vulnerabilities. Attackers have always used automated scanning, but AI lets them find and weaponize vulnerabilities with less skill than ever.
“AI is not going to triage its way out of this problem, and we have the data to prove it,” said David Lindner, Chief Information Security Officer at Contrast Security. “These tools disagree with each other; they disagree with themselves from one run to the next, and none of them can tell me how my application behaves when someone is actually attacking it. That is fine when AI is one input among several. It is a problem when it becomes the system of record, because that is what decides what my team works on Monday morning.”
“For twenty years the discipline of AppSec has been organized around a race: find the vulnerability, decide if it matters, and fix it before somebody with bad intent finds it first,” said Jeff Williams, Founder and CTO at Contrast Security, “AI ended that race, and defenders lost it. We are now seeing vulnerabilities weaponized in hours while the average critical fix takes weeks or months. You cannot close that gap by scanning harder or hiring more people. The only solution that stands the test of time is to defend applications and APIs from within, at runtime, so defenders can stop guessing and start acting to eliminate the risks that really matter.”

