Press Release

HackerOne Report Reveals Growing Exposure Debt: Vulnerability Backlogs Grew 131% Even as Resolution Time Improved 54%

Nearly 70% of security leaders say validated findings are arriving faster than their teams can resolve them

SAN FRANCISCO, October 7, 2026 – HackerOne, a global leader in Continuous Threat Exposure Management (CTEM), today released its 10th annual HackerOne Security Research Report, revealing that on the H1 Platform, the backlog of validated, unresolved vulnerabilities grew 131% in two years, even as average resolution time improved 54%. This year's report, Exposure Debt: The Next Challenge in Cybersecurity, introduces the urgent challenge security teams are grappling with in the race to stay ahead of attackers.

AI has changed what security researchers can find. In skilled hands, advanced models are surfacing authorization flaws and multi-step attack chains that traditional scanners often miss. Organizations are responding: the average resolution time improved 54% this year, but discovery is outpacing remediation, and the gap between them continues to widen. Every vulnerability an organization knows about and hasn't fixed is a risk it already owns and hasn't paid down. That's Exposure Debt, and it grew 131% in just two years.

Key findings from the report include:

  • Exposure Debt is compounding: Despite the fastest remediation speeds recorded on the H1 Platform, the backlog of known, unresolved findings has still grown 131% over the past two years.
  • Security leaders are feeling the pressure: 75% of surveyed security leaders said their organizations formally track exposure debt, and nearly 70% confirmed that validated findings are entering their systems faster than their teams can fix them.
  • AI vulnerabilities are shifting as systems become more connected: System Prompt Leakage reports increased 557% year over year, Misinformation rose 455%, and Improper Output Handling increased 264%. Prompt injection and sensitive information disclosure continue to account for the largest share of AI vulnerability reports on the platform.

“AI is changing both sides of the security equation. It’s helping researchers find vulnerabilities faster and go deeper, while representing entirely new attack surfaces for them to test,” said Kara Sprague, CEO of HackerOne. “At the same time, nearly 70% of security leaders say findings are piling up faster than their teams can address them. Fixing got faster. It still lost ground. The constraint is no longer discovery; it is everything between a report arriving and a risk being resolved.” 

Additional notable findings from the report include:

  • Researchers have incorporated AI into their workflows: 85% of surveyed researchers are actively upskilling in AI, with nearly three-quarters self-reporting a meaningful increase in valid findings.
  • Complexity is the new frontier: 68% of surveyed researchers have shifted toward higher-complexity, higher-bounty bugs as AI changes how and where researchers spend their time.
  • Remediation is faster than ever: Across HackerOne programs, organizations have cut average resolution time from 135 days to 62 days, a 54% improvement in just two years.
  • Researchers earned a record $89 million from July 2025 to June 2026: Organizations running bug bounty programs on the H1 Platform awarded $89 million to security researchers, an 18% increase over the prior year and the highest annual total in the platform’s history.

“AI hasn’t replaced how I think as a security researcher. It’s changed how much ground I can cover,” said Douglas Day, a top-earning security researcher on HackerOne. “I’ve automated parts of my research process that used to take hours, which gives me more time to focus on the vulnerabilities that require creativity, context, and an understanding of how systems actually work. The researchers who get the most out of AI won’t be the ones who simply turn it on. They’ll be the ones who know how to guide it, question it, and recognize when it has found something worth pursuing. The most valuable skill in the age of AI will be the ability to be flexible and adapt to new tools and technologies as they become available.”

You can read the full report here and register for our upcoming webinar, The Vulnerability Is Validated. The Clock Is Running. Now What?, on Wednesday, November 4, at 12 p.m. ET.

About HackerOne:

HackerOne is a global leader in Continuous Threat Exposure Management (CTEM) and the only solution provider that pairs the simultaneous trust of the Fortune 500 and the world's largest community of security researchers to secure the AI-native enterprise. The H1 Platform unites agentic AI solutions with security researchers' ingenuity to continuously discover, validate, prioritize, and remediate exposures across code, cloud, and AI systems. Through solutions such as agentic and human offensive security testing, AI red teaming, code security, validation, and remediation, HackerOne delivers measurable, continuous reduction of cyber risk for enterprises. Industry leaders, including Anthropic, Crypto.com, General Motors, Goldman Sachs, Lufthansa, Uber, UK Ministry of Defence, and the U.S. Department of Defense, trust HackerOne to safeguard their digital ecosystems. HackerOne was recognized in Gartner’s Emerging Tech Impact Radar: AI Cybersecurity Ecosystem report for its leadership in AI Security Testing.

Frequently Asked Questions (FAQ): 

What is the methodology behind this report?

HackerOne’s 2026 Security Research Report draws on three sources fielded in summer 2026: aggregated, de-identified H1 Platform data (July 2025–June 2026), a survey of 111 security leaders at organizations with $100M+ in annual revenue across six countries (United States, Canada, the United Kingdom, Australia, Singapore, and Germany), and a survey of 408 active HackerOne security researchers. Year-over-year survey comparisons reflect differences between independent samples; the 2026 security leader sample is not limited to HackerOne customers and is not directly comparable to prior-year surveys.

What is Exposure Debt?

Exposure Debt is the accumulation of validated vulnerabilities an organization knows about but hasn't yet resolved. HackerOne’s 2026 Security Research Report found that the backlog of valid, unresolved vulnerability reports grew 131% over two years, even as average resolution time improved 54%.

Why is the vulnerability backlog growing if organizations are fixing vulnerabilities faster?

Incoming validated findings are growing faster than organizations can resolve them. Average resolution time fell from 135 days to 62 days, but nearly 70% of surveyed security leaders said validated findings are still entering their systems faster than their teams can remediate them. The report points to AI-assisted discovery, expanding program scope and rising researcher productivity as factors contributing to the increase.

How is AI changing vulnerability research?

AI is helping researchers automate tasks such as reconnaissance and report writing, allowing them to spend more time on vulnerabilities that require creativity, context and human judgment. 85% of surveyed researchers are actively developing their AI skills, nearly three-quarters report a meaningful increase in valid findings as a result, and 68% have shifted toward more complex, higher-bounty vulnerabilities.

What are the fastest-growing AI vulnerability categories on the HackerOne platform?

By year-over-year growth rate in 2026: System Prompt Leakage (+557%), Misinformation (+455%), and Improper Output Handling (+264%). By total volume, Prompt Injection and Sensitive Information Disclosure remain the most reported categories. The growth reflects expanding attack surface as AI systems connect to external tools, data sources, and business workflows.

What should security leaders prioritize to reduce Exposure Debt?

Security leaders should pair continuous vulnerability discovery with stronger validation, prioritization and remediation processes. This includes tracking resolution time alongside backlog age and severity, assigning clear ownership for validated findings, expanding security testing to AI and agentic systems, and establishing accountability for AI-supported security decisions.

How was HackerOne’s 2026 Security Research Report developed?

HackerOne’s 2026 Security Research Report draws on three data sources analyzed or collected during summer 2026: aggregated and de-identified H1 Platform data from July 2025 through June 2026; a survey of 111 security leaders at organizations with more than $100 million in annual revenue across six countries; and a survey of 408 active HackerOne security researchers. Year-over-year survey findings compare independent respondent samples. The 2026 security leader survey included both HackerOne customers and non-customers and is not directly comparable with prior-year surveys. For this report, 2026 refers to the period from July 2025 through June 2026.