Observed Signal · Feb 18, 2026 · Technical Release · Source: https://martechseries.com/feed/ · Impact: 3/5 · Sentiment: Negative
APIs: The Most Vulnerable Attack Surface Exposed
Wallarm published the 2026 API ThreatStats Report, analysing 2025 API attack telemetry, published vulnerabilities, confirmed exploitation, and disclosed API-related breaches. Wallarm examined 67,058 published 2025 vulnerabilities and found 11,053 (17%) were API-related; CISA KEV additions in 2025 were 43% API-related. The report identified 2,185 AI-related vulnerabilities with 786 (36%) overlapping APIs, and found AI-platforms/tooling accounted for 15% of API-related breaches in 2025. Model Context Protocol (MCP) emerged as a fast-growing API/AI control-plane risk (315 MCP-related vulnerabilities; 14% of AI vulns; 270% growth Q2→Q3). Wallarm reports that most API vulnerabilities are trivial and remote to exploit (97% exploitable with a single request; 98% easy/trivial; 99% remotely exploitable; 59% require no authentication). The analysis emphasises repeatable identity, access-control and exposure failures driving large-scale automated exploitation.
APIs (and API-mediated AI) are shown to be the primary exploited surface with high, automated exploitability; this materially raises operational and security risk for enterprises integrating AI and external services and calls for industry-level changes to identity, access control and real-time defenses.
Track Similarweb Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- Wallarm released the 2026 API ThreatStats Report analyzing 2025 API vulnerabilities and breaches.
- Out of 67,058 published vulnerabilities in 2025, 11,053 (17%) were API-related.
- 43% of CISA KEV additions in 2025 were API-related.
- There were 2,185 AI-related vulnerabilities in 2025, with 786 (36%) overlapping API-related vulnerabilities.
- Wallarm found 97% of API vulnerabilities are exploitable with a single request, 98% are easy/trivial to exploit, 99% are remotely exploitable, and 59% require no authentication.
Connected Companies & Entities
1 Entity mappedOntology Mapping & Concepts
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
Only 1% of AI-found Vulnerabilities Were Exploited
Security researchers analyzing AI-assisted vulnerability reports found that only a very small share of flaws discovered by AI were actively exploited. Vuln Check examined 1,061 AI-related reports using datasets that included cybersecurity reports referencing Anthropic and data from the Berkeley Vulnerability Research Initiative. Of those reports, only 14 vulnerabilities showed evidence of active exploitation. The researchers note that AI increases the number of discovered vulnerabilities and can help defenders find and fix issues, but the time between disclosure and exploitation has shortened—from about 120 days in 2025 to 80 days in the first half of 2026—so defenders must remain vigilant as the technology and threat dynamics evolve.
Google Report: AI Doubles Software Vulnerability Disclosures
Google's Threat Intelligence Group reports that the number of disclosed software vulnerabilities has doubled within months, rising from 5,045 in January 2026 to 10,740 by August 2026. The report attributes this surge to the increasing use of AI agents in security research, which uncover different types of flaws than traditional scanners. Notably, 50% of AI-found vulnerabilities lead to remote code execution, compared to 26% for conventionally discovered ones. The report also highlights a rise in exploitation of known 'N-day' vulnerabilities, from 28 in all of 2025 to 75 between January and August 2026, likely accelerated by AI-assisted exploit creation. Additionally, vulnerabilities in AI infrastructure itself are growing, with over 1,500 reports in 2026, focusing on orchestration frameworks like Langflow and inference servers such as vLLM and Ollama. The report advises prioritizing patches based on threat intelligence and recommends AI-powered code reviews for software vendors.
AI Increasing Cyberattack Risk and Supply-Chain Threats
The article argues that AI is amplifying cybersecurity risk in two ways: by expanding the attack surface when platforms add AI features (new data pipelines, APIs, third‑party models, real‑time flows) and by acting as a weapon for attackers (AI‑generated phishing, voice cloning, deepfakes). It cites several incidents: in June 2026 attackers manipulated an AI‑powered account recovery flow to access Instagram accounts (impacting Meta); a May 11, 2026 supply‑chain compromise published 84 malicious versions across 42 @tanstack/* npm packages (19:20–19:26 UTC) that could exfiltrate credentials and affected downstream projects including Grafana Labs, OpenAI, and Vercel; and Microsoft-tracked Tycoon2FA generated tens of millions of phishing emails, linked to ~100,000 compromised organizations. The author urges developers to audit dependencies, harden CI/CD, treat AI integrations as third‑party dependencies, and train users about new social‑engineering risks.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
