• News In Brief
  • Awards nights
  • AI
  • Education
  • Pro AV
  • Case Study
  • Interview
No Result
View All Result
SUBSCRIBE
Smart Solutions World
  • News In Brief
  • Awards nights
  • AI
  • Education
  • Pro AV
  • Case Study
  • Interview
No Result
View All Result
No Result
View All Result
Home News In Brief

Barracuda New research – The average web application has 20 security vulnerabilities and most stem from basic oversights

SmartSolutionUser1 by SmartSolutionUser1
August 31, 2026
in News In Brief
0
Barracuda New research – The average web application has 20 security vulnerabilities and most stem from basic oversights
76
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter

New Barracuda research shows that the average web application carries 20 security vulnerabilities that could be exploited by attackers to steal data, compromise accounts or gain unauthorized access to systems. The findings are detailed in a new report, which also reveals that the most common vulnerabilities stem from preventable security misconfigurations and oversights.

You might also like

Sonos Introduces Sonos 27, the Next Generation of Its Audio Operating System

Global AI and Computational Intelligence Experts Convene at Mahindra University’s ICETCI 2026

5Tattva Highlights Integrated Cybersecurity and Compliance Approach at Cyber Warrior 40

Researchers analyzed hundreds of Barracuda Application Security Insight scans over five months in 2026. They identified seven key types of vulnerability, which between them represent approximately 90% of all the vulnerabilities detected.

These include:

  • Information disclosure. Accounting for 25% of the security flaws detected, this is where the application reveals too much information about its systems, domains, hidden pages, routes or services. Attackers can use such data to map the target’s environment, identify weak points, discover hidden endpoints, find hidden admin areas and plan more targeted attacks – all while remaining undetected.
  • Brand impersonation and spoofing. Accounting for 23% of the security flaws detected, these are weaknesses that make it easier for attackers to impersonate a trusted brand, website or domain and deceive users into sharing credentials or sensitive information.Attackers can use compromised identities to clone web pages, redirect users to malicious sites, steal logins or send believable phishing email using the brand.

● Client-side attacks (browser exploitation). These are weaknesses in how web pages display or execute content, allowing attackers to run malicious scripts in a user’s browser. Client-side attack exposure accounts for 14% of the security flaws detected, and attackers could exploit this to inject scripts (Cross-Site Scripting (XSS)), for example to steal session cookies,alter visible content, trick users into clicking hidden buttons or upload misleading files.

  • Data exposure accounts for 10% of detected security flaws. This is where sensitive information is exposed unnecessarily through the application, for examples through webpages, APIs, logs, cookies, tracking scripts or misconfigured responses. Attackers can exploit this to collect personal data, tokens, private content, secrets or confidential business information, including emails and configuration settings; track users without their consent,andtamper with access controls and data retention policies.
  • Completing the list are weak or missing encryption that allows attackers to intercept or manipulate traffic (accounting for 6% of flaws), outdated software or insecure configurations, (also 6%), and weaknesses in how user sessions are managed, and cookies and credentials are protected, (5%).
Mr. Jesus Cordero-Guzman, Director, Solution Architects AppSec, NetSec & XDR International at Barracuda.
Mr. Jesus Cordero-Guzman, Director, Solution Architects AppSec, NetSec & XDR International at Barracuda.

“Web applications are a critical interface for organizations – from website storefronts to interactive interfaces for customers, partners and operations. Keeping them secure is essential,” said Mr. Jesus Cordero-Guzman, Director, Solution Architects AppSec, NetSec & XDR International at Barracuda. “An average of 20 vulnerabilities per application means attackers have multiple opportunities to probe, test and exploit weaknesses. While not every issue is critical on its own, attackers often chain together several low- and medium-risk vulnerabilities to expose sensitive information, steal credentials or gain unauthorized access. Organizations need a proactive, layered approach to application security that continuously identifies and addresses risks before they can be exploited.”

To reduce web application risk, it is recommended that organizations:

  • Regularly scan for vulnerabilities and security misconfigurations.
  • Patch and update applications, frameworks and dependencies promptly.
  • Minimize information disclosure and exposed sensitive data.
  • Strengthen encryption, authentication and session security controls.
  • Monitor web applications continuously for suspicious activity and emerging threats.

If you have an interesting Article / Report/case study to share, please get in touch with us at editors@roymediative.com roy@roymediative.com, 9811346846/9625243429

Tags: 20 securityaverage web applicationBarracudaNew researchoversightssmart solutions worldVulnerabilities
Share30Tweet19
SmartSolutionUser1

SmartSolutionUser1

Recommended For You

Sonos Introduces Sonos 27, the Next Generation of Its Audio Operating System

by SmartSolutionUser1
September 4, 2026
0
Sonos Introduces Sonos 27, the Next Generation of Its Audio Operating System

Sonos introduced Sonos 27, the latest version of the audio operating system the company has spent more than two decades building. Sonos 27 brings a new set of...

Read moreDetails

Global AI and Computational Intelligence Experts Convene at Mahindra University’s ICETCI 2026

by SmartSolutionUser1
September 4, 2026
0
Global AI and Computational Intelligence Experts Convene at Mahindra University’s ICETCI 2026

The Sixth International Conference on Emerging Techniques in Computational Intelligence (ICETCI 2026) held at Mahindra University brought together researchers, academics, technology leaders and industry experts to discuss emerging...

Read moreDetails

5Tattva Highlights Integrated Cybersecurity and Compliance Approach at Cyber Warrior 40

by SmartSolutionUser1
September 4, 2026
0
5Tattva Highlights Integrated Cybersecurity and Compliance Approach at Cyber Warrior 40

5Tattva, a CERT-In empanelled cybersecurity solutions provider and PCI QSA company, participated in Cyber Warrior 40 – Delhi, a CXO Hub leadership initiative that brought together senior cybersecurity...

Read moreDetails

Qlik Expands MCP Availability across AWS and Databricks Marketplace Bringing Trusted Business Context to Agents

by SmartSolutionUser1
September 3, 2026
0
Qlik Expands MCP Availability across AWS and Databricks Marketplace Bringing Trusted Business Context to Agents

Qlik® announced expanded availability of its Model Context Protocol (MCP) server with Amazon Web Services (AWS) and Databricks, making it easier for customers to connect assistants and agents...

Read moreDetails

Commvault Integrates Cyber Recovery Actions into CrowdStrike Charlotte Agentic SOAR Workflows

by SmartSolutionUser1
September 2, 2026
0
Commvault Integrates Cyber Recovery Actions into CrowdStrike Charlotte Agentic SOAR Workflows

Commvault,a leader in unified resilience at enterprise scale, announced a new integration with CrowdStrike that makes Commvault cyber recovery actions available as native steps within Charlotte Agentic SOAR...

Read moreDetails
Next Post
The AI Era Is Rewriting India’s Executive Hiring Playbook – Randstad Digital

The AI Era Is Rewriting India’s Executive Hiring Playbook - Randstad Digital

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Browse by Category

Browse by Category

Smart Solutions World

We bring you the best Premium news, magazine, personal blog, etc. Check our landing page for details.

  • News In Brief
  • Awards nights
  • AI
  • Education
  • Pro AV
  • Case Study
  • Interview

BROWSE BY TAG

Agentic AI AI AI-powered Akamai AMD CloudKeeper Coforge CrowdStrike Cybersecurity Databricks Fortinet Gartner Google Cloud HCLTech Honeywell IBM India Infosys Kaspersky Keysight Kramer Microsoft New Relic Nvidia OpenAI Palo Alto Networks PPDS Qlik Qualcomm Seqrite ServiceNow SiMa.ai smart solutions world smartsolutionsworld smart solutions world latest news Snowflake Software Solutions Sophos Tata Communications Tech Mahindra Technology Tenable UiPath Vertiv

© 2024 NCN - Premium news & magazine by NCN.

No Result
View All Result
  • News In Brief
  • Awards nights
  • AI
  • Education
  • Pro AV
  • Case Study
  • Interview

© 2024 NCN - Premium news & magazine by NCN.

Not enough quota to unlock this post
Unlock left : 0
Are you sure want to cancel subscription?