Three-Quarters of Firms Knowingly Ship Vulnerable Code

Three-Quarters of Firms Knowingly Ship Vulnerable Code

A damning Checkmarx survey exposes an industry-wide gamble with security debt — and AI is about to make the odds far worse.

Written by OutOfToken AI

June 4, 2026 · 4 min read · Synthesized from reporting by Infosecurity Magazine · How this works

AI Likely Accurate · 6/10

Seventy-five percent of organizations admit they regularly or occasionally deploy software they already know is vulnerable. That figure, drawn from new Checkmarx research published on May 21, represents not ignorance but a calculated — and increasingly dangerous — trade-off between speed and security. With AI-generated code flooding pipelines and third-party suppliers escaping meaningful vetting, the conditions for a systemic supply-chain catastrophe are quietly being assembled.

A Calculated Gamble, Not an Oversight

The Checkmarx data makes clear that most organizations shipping vulnerable code are doing so with eyes open. Development teams face relentless pressure to hit release windows, and when security findings stack up in the backlog, the path of least resistance is often to ship and patch later — a strategy that rarely plays out as planned. What makes this year's figure marginally better than the prior year's is cold comfort: the absolute number of organizations playing this game remains extraordinary, and the downstream consequences of each deliberate bypass accumulate quietly until they don't. Security debt, unlike financial debt, tends to settle in a single catastrophic event rather than gradual decline.

AI Code Is Accelerating the Problem

The arrival of AI-assisted development has turbocharged output without proportionally improving security review capacity. Large language models generate syntactically plausible code that can carry subtle vulnerabilities — insecure deserialization, improper input validation, hardcoded credentials — that automated static analysis tools may flag but overwhelmed teams deprioritize. Checkmarx's research lands alongside a parallel body of evidence suggesting that AI-generated contributions are entering codebases faster than security organizations can audit them. The result is a widening gap between the volume of code in production and the fraction of it that has received meaningful security scrutiny.

""75% of organizations often or sometimes deploy code they know is vulnerable" — Checkmarx, May 2025. Three independent studies published the same week reached the same conclusion."

Supply Chains Amplify Every Shortcut

The risk calculus changes dramatically when vulnerable code travels downstream through the software supply chain. A single compromised dependency or unaudited third-party component can propagate a flaw across hundreds of organizations simultaneously — a dynamic illustrated brutally by incidents like SolarWinds and the Log4Shell crisis. Firms that knowingly ship vulnerable internal code are, in effect, making that decision on behalf of every customer and partner integrating their software. Supplier vetting remains inconsistent across the industry; many organizations still lack formal processes to assess the security posture of their software vendors, creating invisible concentrations of risk that only become legible after a breach. AI tools sourcing packages from public repositories without provenance checks add another uncontrolled vector.

The numbers have barely moved despite years of high-profile supply-chain attacks, regulatory pressure, and executive pledges to treat security as a first-class concern. Until organizations restructure incentives — tying release approval to security gates, investing in developer security training, and imposing real accountability on suppliers — the 75% figure will remain stubbornly close to where it is today. The next generation of AI-accelerated pipelines will stress those incentives further. The question is whether the industry course-corrects before a wave of AI-introduced vulnerabilities makes the current threat landscape look manageable by comparison.

Editorial Note

Infosecurity Magazine is a reputable cybersecurity publication with established credibility. The '75% of firms' statistic likely derives from a legitimate survey (possibly Synopsys, Snyk, or similar 2023-2024 security reports showing high rates of vulnerable dependency shipping). However, the claim requires verification of the original study methodology, sample size, and whether 'knowingly' implies deliberate choice versus negligence or resource constraints.

Claim Tracker

AI-assessed

UnverifiedSeventy-five percent of organizations admit they regularly or occasionally deploy software they already know is vulnerable

Attributed to Checkmarx research published May 21, but specific study link not provided. Claim is specific and testable but requires access to original report.

UnverifiedThis year's figure is marginally better than the prior year's

No specific prior-year percentage provided. Suggests improvement but baseline and comparison methodology unclear.

UnverifiedAI-generated code is flooding pipelines

Vague claim without quantification or citations. The extent of AI-generated code adoption in industry pipelines is not substantiated.

UnverifiedThird-party suppliers are escaping meaningful vetting

Broad assertion without data or examples. 'Meaningful vetting' is subjective and lacks definition.

UnverifiedThe 'ship and patch later' strategy rarely plays out as planned

Intuitive claim but presented without supporting evidence or case studies.

Ask AI about this story

// discussion

sign in to join the discussion