Veracode’s analysis of 1.6 million applications shows what government agencies
and SLED organizations can do to reduce mounting security debt.
82% of organizations carry security debt – known vulnerabilities sitting unresolved for
over a year – and critical security debt surged 20% in a single year, now hitting 60% of
organizations. Nation-state actors, ransomware groups, and opportunistic attackers go
after precisely this class of flaw: highly severe, highly exploitable, and sitting open.
This report translates Veracode’s 2026 State of Software Security findings into a
concrete framework for Federal agencies and SLED organizations to prioritize, remediate,
and get ahead of the threats.