The average web application carries around 20 security vulnerabilities, any one of which could let attackers steal data, hijack accounts, or slip into company systems, according to new research from cybersecurity firm Barracuda.
The findings come from an analysis of hundreds of Application Security Insight scans conducted over five months in 2026. Researchers found that just seven vulnerability categories account for roughly 90% of everything detected.
Oversharing Is the Biggest Culprit
The biggest issue, accounting for a quarter of all flaws, is information disclosure apps revealing more than they should about internal systems, hidden pages, or services. This gives attackers a roadmap to plan focused attacks without tipping anyone off.
Close behind, at 23%, are weaknesses that make it easier for criminals to impersonate a trusted brand or website, often to trick users into handing over passwords or launch convincing phishing campaigns.
Browsers And Data Are Also At Risk
Client-side attacks — where malicious code runs inside a user’s browser made up 14% of flaws, opening the door to stolen session cookies or manipulated web pages. Another 10% involved unnecessary exposure of sensitive data through APIs, logs, or cookies.
Rounding out the list: weak encryption, outdated software, and poor session or credential management, each contributing a smaller but still meaningful share of risk.
Small Flaws Add Up To Big Breaches
A Barracuda executive noted that attackers rarely need one major flaw; they often chain together several minor ones to gain unauthorised access or steal sensitive information.
To limit exposure, the report urges organisations to scan applications regularly, patch software promptly, reduce unnecessary data exposure, tighten encryption and authentication, and continuously monitor for suspicious activity.
With web applications now central to how businesses interact with customers and partners, the report reminds organisations that basic security hygiene remains a persistent blind spot.
