HackerOne Security Research Report 2026

Security teams are fixing faster. So why is the backlog growing?

Critical vulnerabilities are being resolved 61% faster than two years ago. Yet the backlog of valid, unresolved findings has grown 131%. 

That gap is Exposure Debt.

Image
hpsr
In the report

Faster fixes. A bigger backlog.

Security teams are resolving critical vulnerabilities faster. Yet the backlog of valid, unresolved findings keeps growing.

It builds when discovery outpaces an organization’s ability to validate, prioritize, and remediate findings, leaving engineering teams without the clarity or confidence to act quickly.

Managing Exposure Debt is what a mature continuous threat exposure management (CTEM) program is built to do: continuously identify, validate, prioritize, and reduce the exposures that matter most.

The 10th Edition of the HackerOne Security Research Report reveals where Exposure Debt is growing, what’s driving it, and how security leaders can respond.
 

131%
The backlog is growing.

Open valid reports increased 131% from 2024 to 2026.
 

61%
Teams are fixing faster.

Average resolution time for critical findings fell 61% in two years.

$89.1M
Research keeps accelerating.

Bounty payouts to researchers, July 2025–June 2026.

TURN RESEARCH INTO ACTION

The data shows where security teams are falling behind. Here's how to move forward.

The finding
70%
of security leaders say validated findings are entering their backlog faster than their teams can remediate them.
Hover to see the question
The question
What happens when finding vulnerabilities scales faster than fixing them?

Explore H1 Remediation →

The finding
54% faster
Across all severities, average resolution time improved from 135 days to 62 days. Yet the open backlog continued to grow.
Hover to see the question
The question
If resolution time is improving, what is the backlog telling you that your headline metric isn't?

Explore H1 Platform →

The finding
30 hrs
Security leaders report an average of 30 hours to validate a critical finding.
Hover to see the question
The question
How much exposure exists before remediation even starts?

Explore HackerOne AI, Hai →

The finding
222%
Valid AI vulnerability reports grew 222% in two years — with system prompt leakage up 557%, misinformation 455%, and improper output handling 264%.
Hover to see the question
The question
AI is creating new attack surfaces. How much of yours has actually been tested like an attacker would?

Explore H1 AI Red Teaming →

10 years of security research

Ten years of data reveal where security is headed next.

For the 10th Edition, we asked security leaders who have spent the past decade in the trenches to reflect on what changed, what surprised them, and what the next decade will demand.

HackerOne Security Research Report

Frequently asked questions

Exposure Debt is the growing gap between what security teams discover and what they can fix. It builds when findings come in faster than teams can validate and fix them, when critical bugs sit in queue for months, and when the handoff from security to engineering breaks down. The 10th Edition of the HackerOne Security Research Report is the first to quantify it at scale.

HackerOne's flagship annual benchmark, now in its tenth year. Since 2017, it has tracked how vulnerabilities are discovered and mitigated across industries. This year's edition draws on 92,194 valid vulnerability reports, $89.1M in bounty payouts, and survey data from 111 security leaders and 408 active researchers.

Security leaders, CISOs, and practitioners who want to benchmark their programs against real-world data, understand where attacker focus is shifting, and make the case for security investment in terms that boards and executive teams understand.

Last year's report introduced the Bionic Hacker and tracked the surge in AI vulnerability reports. This year follows the consequences: what happens when discovery accelerates faster than organizations can fix. Exposure Debt is what this year's report measures.

The report includes median, average, and 95th percentile maximum bounties by industry and severity. Use these to benchmark your program's reward structure against peers, identify where your program may be underpriced relative to risk, and make the case for competitive bounty investment.

Source code vulnerability reports tripled year over year. The open critical backlog grew 123% in two years even as resolution time for critical findings dropped 61%. When AI gets a security decision wrong, 39% of organizations say the CISO takes the blame. Only 10% have a formal framework for who owns that call.

Continuous threat exposure management (CTEM) is an ongoing approach to identifying, validating, prioritizing, and reducing the exposures that matter most. With the open backlog of valid reports up 131% even as critical resolution time fell 61%, the research shows why mature CTEM requires organizations to manage Exposure Debt, not just accelerate discovery.

HackerOne’s 2026 Security Research Report draws on three sources fielded in summer 2026: aggregated H1 Platform data (July 2025–June 2026), a survey of 111 security leaders at organizations with $100M+ in annual revenue across six countries (United States, Canada, the United Kingdom, Australia, Singapore, and Germany), and a survey of 408 active HackerOne security researchers. Year-over-year survey comparisons reflect differences between independent samples; the 2026 security leader sample is not limited to HackerOne customers and is not directly comparable to prior-year surveys.