Security teams are fixing faster. So why is the backlog growing?
Critical vulnerabilities are being resolved 61% faster than two years ago. Yet the backlog of valid, unresolved findings has grown 131%.
That gap is Exposure Debt.
Faster fixes. A bigger backlog.
Security teams are resolving critical vulnerabilities faster. Yet the backlog of valid, unresolved findings keeps growing.
It builds when discovery outpaces an organization’s ability to validate, prioritize, and remediate findings, leaving engineering teams without the clarity or confidence to act quickly.
Managing Exposure Debt is what a mature continuous threat exposure management (CTEM) program is built to do: continuously identify, validate, prioritize, and reduce the exposures that matter most.
The 10th Edition of the HackerOne Security Research Report reveals where Exposure Debt is growing, what’s driving it, and how security leaders can respond.
Open valid reports increased 131% from 2024 to 2026.
Average resolution time for critical findings fell 61% in two years.
Bounty payouts to researchers, July 2025–June 2026.
TURN RESEARCH INTO ACTION
The data shows where security teams are falling behind. Here's how to move forward.
Ten years of data reveal where security is headed next.
For the 10th Edition, we asked security leaders who have spent the past decade in the trenches to reflect on what changed, what surprised them, and what the next decade will demand.
Frequently asked questions
Exposure Debt is the growing gap between what security teams discover and what they can fix. It builds when findings come in faster than teams can validate and fix them, when critical bugs sit in queue for months, and when the handoff from security to engineering breaks down. The 10th Edition of the HackerOne Security Research Report is the first to quantify it at scale.
HackerOne's flagship annual benchmark, now in its tenth year. Since 2017, it has tracked how vulnerabilities are discovered and mitigated across industries. This year's edition draws on 92,194 valid vulnerability reports, $89.1M in bounty payouts, and survey data from 111 security leaders and 408 active researchers.
Security leaders, CISOs, and practitioners who want to benchmark their programs against real-world data, understand where attacker focus is shifting, and make the case for security investment in terms that boards and executive teams understand.
Last year's report introduced the Bionic Hacker and tracked the surge in AI vulnerability reports. This year follows the consequences: what happens when discovery accelerates faster than organizations can fix. Exposure Debt is what this year's report measures.
The report includes median, average, and 95th percentile maximum bounties by industry and severity. Use these to benchmark your program's reward structure against peers, identify where your program may be underpriced relative to risk, and make the case for competitive bounty investment.
Source code vulnerability reports tripled year over year. The open critical backlog grew 123% in two years even as resolution time for critical findings dropped 61%. When AI gets a security decision wrong, 39% of organizations say the CISO takes the blame. Only 10% have a formal framework for who owns that call.
Continuous threat exposure management (CTEM) is an ongoing approach to identifying, validating, prioritizing, and reducing the exposures that matter most. With the open backlog of valid reports up 131% even as critical resolution time fell 61%, the research shows why mature CTEM requires organizations to manage Exposure Debt, not just accelerate discovery.
HackerOne’s 2026 Security Research Report draws on three sources fielded in summer 2026: aggregated H1 Platform data (July 2025–June 2026), a survey of 111 security leaders at organizations with $100M+ in annual revenue across six countries (United States, Canada, the United Kingdom, Australia, Singapore, and Germany), and a survey of 408 active HackerOne security researchers. Year-over-year survey comparisons reflect differences between independent samples; the 2026 security leader sample is not limited to HackerOne customers and is not directly comparable to prior-year surveys.