Barracuda new research flags hidden web security risks

Web applications remain a key interface for websites, customers, partners and business operations. But new findings from Barracuda suggest that many applications still carry security gaps that attackers could exploit.
The Barracuda New research analysed hundreds of Barracuda Application Security Insight scans collected over five months in 2026. The findings identified seven major vulnerability types that together accounted for around 90% of all detected flaws.
Application security insight points to common gaps
Information disclosure was the most common issue, accounting for 25% of detected vulnerabilities. These flaws can reveal details about systems, domains, hidden pages, routes or services, giving attackers more information to map an application and identify potential weak points.
Brand impersonation and spoofing followed at 23%. Such weaknesses can make it easier for attackers to imitate trusted websites or domains and trick users into sharing credentials or sensitive information.
Client-side attacks accounted for 14%. These weaknesses can allow malicious scripts to run in browsers, potentially exposing session cookies or changing visible content.
Web application vulnerabilities extend beyond code
Data exposure made up another 10% of detected flaws. The research points to possible exposure through webpages, APIs, logs, cookies, tracking scripts and misconfigured responses.
The remaining vulnerabilities included weak or missing encryption at 6%, outdated software or insecure configurations at another 6%, and weaknesses involving sessions, cookies and credentials at 5%.
The pattern is notable because several of the leading issues relate to how applications are configured, exposed and maintained rather than a single type of attack.
Cybersecurity needs continuous attention
Barracuda said an average of 20 vulnerabilities per application gives attackers multiple opportunities to probe and test weaknesses. The company also noted that attackers can chain several low- and medium-risk vulnerabilities to reach sensitive information or credentials.
For organisations, the findings point towards a layered approach to cybersecurity. Regular vulnerability scanning, timely patching, stronger encryption and authentication, and continuous monitoring are among the measures recommended.
Read More:
Redington Global NEXT 2026 brings 400 tech leaders together
Savex Technologies and PeopleLink partnership to Scale Workplace Collaboration in India
Ingram Micro AI adoption is changing channel workflows
Blue Machines AI launches Floe to rethink language switching






