Phone : +91 95 8290 7788 | Email : sales@itmonteur.net

Register & Request Quote | Submit Support Ticket

Home » Cyber Security News » Study finds average web application harbors 20 security vulnerabilities due to basic oversights

Study finds average web application harbors 20 security vulnerabilities due to basic oversights

Study finds average web application harbors 20 security vulnerabilities due to basic oversights

https://etimg.etb2bimg.com/thumb/msid-133602385,imgsize-1323603,width-1200,height=627,overlay-etciso,resizemode-75/vulnerabilities-exploits/study-finds-average-web-application-harbors-20-security-vulnerabilities-due-to-basic-oversights.jpg

New Barracuda research shows that the average web application carries 20 security vulnerabilities that could be exploited by attackers to steal data, compromise accounts or gain unauthorized access to systems. The findings are detailed in a new report, which also identifies preventable security misconfigurations and oversights as the most common sources of vulnerabilities.

Researchers analyzed hundreds of web application security scans conducted over five months in 2026. They identified seven key types of vulnerabilities, which together accounted for approximately 90% of all vulnerabilities detected.

These include:

Information disclosure: Accounting for 25% of the security flaws detected, this occurs when applications reveal excessive information about systems, domains, hidden pages, routes or services. Attackers can use such information to map a target’s environment, identify weak points, discover hidden endpoints and administrative areas, and plan targeted attacks.

Brand impersonation and spoofing: Representing 23% of detected flaws, these weaknesses can enable attackers to impersonate trusted brands, websites or domains and deceive users into sharing credentials or sensitive information. Compromised identities can also be used to clone web pages, redirect users to malicious sites, steal logins or send phishing emails.

Client-side attacks (browser exploitation): Accounting for 14% of security flaws, these weaknesses involve how web pages display or execute content, potentially allowing attackers to run malicious scripts in users’ browsers. Exploitation can include cross-site scripting (XSS), which may be used to steal session cookies, alter visible content, manipulate user interactions or upload misleading files.

Data exposure: Data exposure accounted for 10% of detected flaws. Sensitive information can be unnecessarily exposed through webpages, APIs, logs, cookies, tracking scripts or misconfigured responses. Attackers can exploit these exposures to obtain personal data, tokens, private content, credentials and confidential business information.

The remaining vulnerabilities included weak or missing encryption, accounting for 6% of flaws; outdated software or insecure configurations, also at 6%; and weaknesses in user-session management and the protection of cookies and credentials, accounting for 5%.

“Web applications are a critical interface for organizations – from website storefronts to interactive interfaces for customers, partners and operations. Keeping them secure is essential,” said Jesus Cordero-Guzman, Director, Solution Architects AppSec, NetSec & XDR International at Barracuda. “An average of 20 vulnerabilities per application means attackers have multiple opportunities to probe, test and exploit weaknesses. While not every issue is critical on its own, attackers often chain together several low- and medium-risk vulnerabilities to expose sensitive information, steal credentials or gain unauthorized access.”

To reduce web application risk, organizations should:

•Regularly scan for vulnerabilities and security misconfigurations.

•Patch and update applications, frameworks and dependencies promptly.

•Minimize information disclosure and exposure of sensitive data.

•Strengthen encryption, authentication and session security controls.

•Continuously monitor web applications for suspicious activity and emerging threats.

  • Published On Aug 29, 2026 at 08:00 AM IST

Join the community of 2M+ industry professionals.

Subscribe to Newsletter to get latest insights & analysis in your inbox.

All about ETCISO industry right on your smartphone!




Information Security - InfoSec - Cyber Security - Firewall Support Providers Company in India

 

What is Firewall? A Firewall is a network security device that monitors and filters incoming and outgoing network traffic based on an organization's previously established security policies. At its most basic, a firewall is essentially the barrier that sits between a private internal network and the public Internet.

 

Secure your network at the gateway against threats such as intrusions, Viruses, Spyware, Worms, Trojans, Adware, Keyloggers, Malicious Mobile Code (MMC), and other dangerous applications for total protection in a convenient, affordable subscription-based service. Modern threats like web-based malware attacks, targeted attacks, application-layer attacks, and more have had a significantly negative effect on the threat landscape. In fact, more than 80% of all new malware and intrusion attempts are exploiting weaknesses in applications, as opposed to weaknesses in networking components and services. Stateful firewalls with simple packet filtering capabilities were efficient blocking unwanted applications as most applications met the port-protocol expectations. Administrators could promptly prevent an unsafe application from being accessed by users by blocking the associated ports and protocols.

 

Firewall Firm is an IT Monteur Firewall Company provides Managed Firewall Support, Firewall providers , Firewall Security Service Provider, Network Security Services, Firewall Solutions India , New Delhi - India's capital territory , Mumbai - Bombay , Kolkata - Calcutta , Chennai - Madras , Bangaluru - Bangalore , Bhubaneswar, Ahmedabad, Hyderabad, Pune, Surat, Jaipur, Firewall Service Providers in India, Welcome to IT Monteur's Firewall Firm, India's No1 Managed Enterprise Network Security Firewall Support Provider Company in India, Firewall Firm Provider Complete range of Juniper Firewall Support , Cisco Firewall Support , Check Point Firewall Support , Palo Alto Firewall Support , FortiGate Firewall Support , Forcepoint Firewall Support , Sophos Firewall Support , WatchGuard Firewall Support , Baracuda Firewall Support , SonicWall Firewall Support , Gajshield Firewall Support , Seqrite Firewall Support , Firewall , Hardware Firewall , Software Firewall , Firewall India , Firewall , Network Firewall , Firewall Support , Firewall Monitoring , Firewall VPN , WAF Website Firewall , Firewall Security , Firewall India , Firewalls Support Provider in India , Firewall Support Services Provider Company in India

Sales Number : +91 95 8290 7788 | Support Number : +91 94 8585 7788
Sales Email : sales@itmonteur.net | Support Email : support@itmonteur.net

Register & Request Quote | Submit Support Ticket