Skip to main content
HomeTopicsAPIs

APIs

Cybersecurity statistics about apis

Showing 1-20 of 42 results

In 2025, 36% of AI-related vulnerabilities involved APIs (786 of 2,185 AI-related vulnerabilities).

Wallarm2/22/2026
AI-related VulnerabilitiesAPI Security

62% of security professionals are blind to shadow or undocumented APIs.

Rein Security2/22/2026
Application SecurityShadow APIs

In 2025, 43% of CISA KEV additions were API-related, making APIs the single largest exploited surface in that dataset.

Wallarm2/22/2026
API SecurityKEV

82% of the more than 10,000 Model Context Protocol (MCP) servers interact with sensitive APIs, creating additional vulnerabilities in 2025.

Endor Labs11/9/2025
MCP EcosystemSoftware Development

APIs in technology & SaaS providers' environments saw a 400% spike in critical vulnerabilities.

BreachLock8/11/2025
VulnerabilitiesCritical vulnerabilities

Nearly 7 in 10 retail & consumer goods organizations had APIs with misconfigured authorizations or data exposure issues. These retail & consumer goods APIs averaged 15 vulnerabilities per API.

BreachLock8/11/2025
MisconfigurationData exposure

In one analysis, retail had 27% of vulnerable assets across cloud, APIs, and web applications.

CyCognito7/15/2025
RetailVulnerabilities

In one analysis, technology had 15% of vulnerable assets across cloud, APIs, and web applications.

CyCognito7/15/2025
TechnologyVulnerabilities

In one analysis, the media sector had 18.8% vulnerable APIs.

CyCognito7/15/2025
MediaVulnerabilities

In one analysis, retail had 29.8% vulnerable APIs.

CyCognito7/15/2025
RetailVulnerabilities

In one analysis, education had 37.7% vulnerable APIs.

CyCognito7/15/2025
EducationVulnerabilities

In one analysis, telecommunications had 15% of vulnerable assets across cloud, APIs, and web applications.

CyCognito7/15/2025
TelecommunicationsVulnerabilities

In one analysis, education had 31% of vulnerable assets across cloud, APIs, and web applications.

CyCognito7/15/2025
EducationVulnerabilities

In one analysis, the government sector had 18.5% vulnerable APIs.

CyCognito7/15/2025
GovernmentVulnerabilities

In one analysis, finance had 5% of vulnerable assets across cloud, APIs, and web applications.

CyCognito7/15/2025
FinanceVulnerabilities

In one analysis, the services sector had 10.6% vulnerable APIs.

CyCognito7/15/2025
Services sectorVulnerabilities

In one analysis, government had 26% of vulnerable assets across cloud, APIs, and web applications.

CyCognito7/15/2025
GovernmentVulnerabilities

In one analysis, health care & insurance had 16% of vulnerable assets across cloud, APIs, and web applications.

CyCognito7/15/2025
HealthcareInsurance

In one analysis, construction had 18% of vulnerable assets across cloud, APIs, and web applications.

CyCognito7/15/2025
ConstructionsVulnerabilities

In one analysis, technology had 15% of vulnerable assets across cloud, APIs, and web applications.

CyCognito7/15/2025
TechnologyVulnerabilities