Cybertech Europe 2026-IT Industry Official Media Partner

New study: The average web application has 20 security flaws

New study: The average web application has 20 security flaws | IT industry New study: The average web application has 20 security flaws | IT industry
New study: The average web application has 20 security flaws

Looking for a Shorter Overview?

Key Moments

Most common security flaws

Seven main types account for 90% of the flaws, with accidental information leakage and trademark counterfeiting at the top.

Risks of security flaws

An average of 20 flaws per app gives attackers many opportunities to exploit weaknesses and gain unauthorized access.

The importance of proactive work

Companies must work in multiple layers and continuously identify and address security risks.

Recommended actions

Regular vulnerability scanning, rapid updates, minimized data exposure, and monitoring improve security.

New research from Barracuda shows that the average web application has 20 security vulnerabilities that attackers can exploit to steal data, hijack accounts or gain unauthorized access to systems. The study also shows that the most common vulnerabilities are often due to security settings and oversights that could have been avoided.

Barracuda security researchers have analyzed hundreds of scans conducted with Barracuda Application Security Insight over five months in 2026. The analysis identified seven main types of security vulnerabilities that together account for around 90 percent of all vulnerabilities discovered.

An average of 20 vulnerabilities per application gives attackers multiple opportunities to search for, test, and exploit weaknesses

The most common are:

  • Accidental disclosure of system information – 25 percent. It is about an application revealing too much information about, for example, systems, domains, hidden pages, search paths or services. Attackers can use the information to map the environment, identify weak points, find hidden functions and administration pages and plan more targeted attacks – without being detected themselves.
  • Brand and identity fraud – 23 percent. Flaws that make it easier for attackers to impersonate a trusted brand, website, or domain and trick users into giving up login credentials or sensitive information. Attackers can clone websites, redirect users to malicious websites, steal login credentials, or send credible phishing emails in the brand’s name, among other things.
  • Attacks via the user's browser – 14 percent. Vulnerabilities in how web pages display or execute content can allow attackers to execute malicious code in a user's browser. For example, Cross-Site Scripting (XSS) can be used to steal session cookies, modify visible content, trick users into clicking hidden buttons, or upload deceptive files.
  • Exposure of sensitive data – 10 percent. Sensitive information is unnecessarily exposed through web pages, APIs, logs, cookies, tracking scripts, or misconfigured responses. Attackers can exploit this to collect personal data, access tokens, private content, secrets, or confidential company information, such as email and configuration data. The flaws can also allow users to be tracked without their consent or to manipulate access and data retention policies.

Other flaws identified include weak or missing encryption that could allow attackers to intercept or manipulate traffic (6 percent), outdated software or insecure configurations (6 percent), and shortcomings in the management of user sessions and the protection of cookies and login credentials (5 percent).

  • VORTIQ-X AI Governance helps companies transform AI into controllable and verifiable business value.
    VORTIQ-X is an AI Governance platform that helps organizations govern, verify, and create measurable business value from AI. The platform focuses on transparency, compliance, AI governance, and the effective use of AI in mission-critical processes.
    ADVERTISEMENT

  • The IT industry Nordic technology media platform covering cybersecurity, cloud, AI, digital transformation, channel, MSP and enterprise IT news
    The IT industry is a leading Nordic technology media platform covering cybersecurity news, artificial intelligence, cloud computing, enterprise IT, digital transformation, managed services, channel partners, software development, telecommunications, data centers, IT infrastructure, technology leadership, business innovation, and emerging technologies. Through executive interviews, industry analysis, event coverage, thought leadership, product launches, vendor updates, and market insights, the IT industry connects technology decision-makers, CIOs, CISOs, CTOs, IT managers, MSPs, resellers, distributors, technology vendors, startups, and enterprise organizations across Sweden, Norway, Denmark, Finland, and Europe. Coverage includes cybersecurity trends, AI adoption, cloud strategy, enterprise software, networking, digital infrastructure, sustainability, compliance, governance, risk management, automation, data analytics, and future technology developments.
    OWN CONTENT

  • Maciek Szczesniak featured on IT-Branschen Wire Channel Magic Chats podcast banner
    Maciek Szczesniak appears on IT-Branschen Wire Channel Magic Chats, discussing leadership, innovation, digital transformation, and business services.
    SPONSORED

  • Cybertech Europe 2026 cybersecurity conference in Rome with the IT industry as Official Media Partner
    Cybertech Europe 2026 is one of Europe's leading cybersecurity conferences, bringing together cybersecurity leaders, government officials, technology innovators, startups, investors, and enterprise decision-makers in Rome. The IT industry serves as an Official Media Partner, providing event coverage, executive interviews, industry insights, and cybersecurity news for Nordic and European audiences.
    ADVERTISEMENT

– Web applications are a central interface for businesses, from digital stores to interactive services for customers, partners and your own business. Therefore, securing them is crucial. An average of 20 security vulnerabilities per application gives attackers multiple opportunities to search for, test and exploit weaknesses, says Jesus Cordero-Guzman, Director, Solution Architects AppSec, NetSec & XDR International at Barracuda.

“While each flaw may not be critical on its own, attackers can combine multiple low- or medium-risk flaws to access sensitive information, steal credentials, or gain unauthorized access. Therefore, companies need to work proactively and in multiple layers with application security so that risks are continuously identified and addressed,” he continues.

Five measures to reduce risks

Barracuda recommends that:

  • regularly scan for vulnerabilities and incorrect security settings
  • quickly install security updates for applications, frameworks, and dependencies
  • minimize the amount of system information and sensitive data exposed
  • strengthen encryption, authentication, and security around user sessions
  • Continuously monitor web applications to detect suspicious activity and new threats.

Read more here.

Related Posts

Cyberattacks against Swedish businesses are increasing most in the Nordic countries

Swedish businesses were exposed to an average of 2,352 cyberattacks per week in July. This is 36 percent more than the previous year and the sharpest increase…

85 percent of Swedish industrial companies have not yet taken AI beyond the pilot stage

Swedish industrial companies have high ambitions for AI, but the path from pilot projects to actual implementation is slow. A new survey from IFS shows that 85 percent…

EU demands more visible AI. VORTIQ-X wants to make the mandate behind the action verifiable

The EU's new transparency requirements show when AI is used, but not who approved that AI was allowed to move data or influence operations. VORTIQ-X wants to make the mandate behind…

Questions Answered

What does the study say about the number of security vulnerabilities in web applications?

An average web application has 20 security vulnerabilities according to Barracuda.

What are the most common security flaws?

Accidental exposure of system information and trademark infringement are most common.

How can attacks occur via these flaws?

Through data theft, account takeover and unauthorized access via various attacks.

What measures are recommended to reduce the risks?

Regular vulnerability scanning, timely updates, and monitoring are recommended.

Stay up to date with the most important news

By pressing the Subscribe button, you confirm that you have read and agree to our privacy policy and terms of use
  • Maciek Szczesniak featured on IT-Branschen Wire Channel Magic Chats podcast banner
    Maciek Szczesniak appears on IT-Branschen Wire Channel Magic Chats, discussing leadership, innovation, digital transformation, and business services.
    SPONSORED

  • VORTIQ-X AI Governance helps companies transform AI into controllable and verifiable business value.
    VORTIQ-X is an AI Governance platform that helps organizations govern, verify, and create measurable business value from AI. The platform focuses on transparency, compliance, AI governance, and the effective use of AI in mission-critical processes.
    ADVERTISEMENT

  • The IT industry Nordic technology media platform covering cybersecurity, cloud, AI, digital transformation, channel, MSP and enterprise IT news
    The IT industry is a leading Nordic technology media platform covering cybersecurity news, artificial intelligence, cloud computing, enterprise IT, digital transformation, managed services, channel partners, software development, telecommunications, data centers, IT infrastructure, technology leadership, business innovation, and emerging technologies. Through executive interviews, industry analysis, event coverage, thought leadership, product launches, vendor updates, and market insights, the IT industry connects technology decision-makers, CIOs, CISOs, CTOs, IT managers, MSPs, resellers, distributors, technology vendors, startups, and enterprise organizations across Sweden, Norway, Denmark, Finland, and Europe. Coverage includes cybersecurity trends, AI adoption, cloud strategy, enterprise software, networking, digital infrastructure, sustainability, compliance, governance, risk management, automation, data analytics, and future technology developments.
    OWN CONTENT

  • Cybertech Europe 2026 cybersecurity conference in Rome with the IT industry as Official Media Partner
    Cybertech Europe 2026 is one of Europe's leading cybersecurity conferences, bringing together cybersecurity leaders, government officials, technology innovators, startups, investors, and enterprise decision-makers in Rome. The IT industry serves as an Official Media Partner, providing event coverage, executive interviews, industry insights, and cybersecurity news for Nordic and European audiences.
    ADVERTISEMENT