Barracuda finds 20 flaws in web application security

DQChannels Bureau
DQChannels Bureau
Barracuda finds 20 flaws in web application security

Web application security may be facing a simpler problem than many organisations expect. New Barracuda research found that the average web application carries 20 security vulnerabilities, creating multiple paths for attackers to steal data, compromise accounts or gain unauthorised access.

The research analysed hundreds of Barracuda Application Security Insight scans over five months in 2026. It found that seven vulnerability types account for about 90% of all detected flaws. More importantly, many of these issues are linked to security misconfigurations and basic oversights.

Security vulnerabilities point to familiar weaknesses

Information disclosure was the largest category, accounting for 25% of detected flaws. These weaknesses can expose details about systems, domains, hidden pages, routes and services.

Brand impersonation and spoofing followed at 23%. Such flaws can help attackers imitate trusted websites or brands and trick users into sharing credentials or sensitive information.

Client-side attacks accounted for 14%, while data exposure made up another 10%. The remaining findings included weak or missing encryption at 6%, outdated software or insecure configurations at 6%, and session, cookie and credential weaknesses at 5%.

The pattern is notable. The report suggests that common security flaws are not always tied to highly complex attacks. Basic coding oversights, exposed information and configuration gaps can create several opportunities for attackers.

Application security oversight can create attack chains

Barracuda said attackers may combine several low- and medium-risk vulnerabilities to expose sensitive information, steal credentials or gain unauthorised access. That makes application security oversight more than a matter of fixing individual flaws.

The research recommends regular vulnerability scans, prompt patching and updates, reduced information disclosure, stronger encryption and authentication, and continuous monitoring for suspicious activity.

For organisations, the takeaway is fairly direct: web application security needs continuous attention rather than a one-time check. The volume of vulnerabilities found in the research shows why even seemingly minor gaps can matter when they are combined.

What organisations can focus on

The report recommends that organisations should regularly scan applications for vulnerabilities and misconfigurations, patch applications, frameworks and dependencies promptly, limit exposed information and sensitive data, strengthen encryption, authentication and session controls, and continuously monitor applications for suspicious activity and emerging threats.

The findings put the focus back on fundamentals. For web application security, reducing preventable weaknesses may be just as important as preparing for sophisticated attacks. 

Read More: 

Apple and Google May Deepen Manufacturing Footprint in India

Autodesk AI Pulse Report 2026 reveals India’s AI shift

Why AI and data security are creating new channel opportunities

RAH Infotech and Quantera Technologies partnership bring cyber risk tools

Latest Stories