Cyber Resilience

Record WatchRecord

CWE-79 has been the most common vulnerability type for over 24 months

23 July 2026 · Timeframe: Monthly top weakness; multi-month streak

CWE-79 Improper Neutraliz…1833CWE-89 Improper Neutraliz…1124CWE-416 Use After Free1109CWE-862 Missing Authoriza…1007CWE-284 Improper Access C…833
Top weakness types, last 90 days · security-resilience.ai

CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')) has led the monthly weakness ranking for at least 24 consecutive months. The same class of flaw is being written into new software, month after month, faster than it is being designed out.

Why it matters

A weakness that stays #1 for years is not a fad; it is a structural gap in how software is built. The durable leaders are where prevention pays back the most.

What to do

Our take

The weaknesses that never leave the top of the list are the ones worth engineering out at the source. Durability is the signal, not novelty.

More records like this: Weakness-type records →