Enterprise applications now carry 4.31 times more critical and high-severity vulnerabilities than before the acceleration of AI-driven software development.
AI-driven software development and a fivefold increase in application creation
Sonatype’s analysis of four years of enterprise software development data finds that the pace of application creation has accelerated almost fivefold in what the firm calls the “AI era.” The report ties that surge directly to the growing use of artificial intelligence in development workflows, saying teams are producing applications at a much faster rate while also carrying more critical and high-severity vulnerabilities.
Faster fixes, but risk growing faster still: the median age of unresolved vulnerabilities
At the same time Sonatype reports a 59% decline in the median age of unresolved vulnerabilities. That metric indicates organizations are reducing the time vulnerabilities stay open — an improvement in remediation speed — even as the absolute volume of risk expands. Sonatype frames this as two concurrent trends: remediation is becoming quicker, yet the acceleration of software creation outstrips those gains.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleThe 4.31x jump in critical and high-severity findings
The headline figure — enterprise applications carry 4.31 times more critical and high-severity vulnerabilities than before AI-driven acceleration — is central to Sonatype’s argument that software creation is moving faster than traditional security processes can absorb. The firm warns this mismatch creates pressure to identify and address risk earlier in development rather than relying on later-stage reviews.
Sonatype’s prescription: move security decisions to the moment of assembly
Sonatype urges a shift in where security decisions happen. “Developers shouldn’t have to choose between moving at AI speed and understanding the software they’re bringing into the organization,” said Mitchell Johnson, chief product development officer at Sonatype. Co-founder and CTO Brian Fox summarized the change in forceful terms: “AI is changing the math of software development. We’re building more software, faster, but we’re also introducing risk faster than traditional security processes can absorb it.”
Sonatype argues the remedy is not to add another post-development review. “The answer can’t be to put another review step at the end. We need to make better decisions at the moment software is assembled, whether that decision is being made by a developer or an AI agent,” Fox said. The firm’s view is that security must be embedded at assembly time so faster creation does not automatically translate into faster introduction of high-severity vulnerabilities.
What this means for developers, security teams, and procurement leaders
- Developers: The report frames a choice that should not be binary — speed or understanding. Sonatype’s commentary suggests developers will need tools and processes that let them work at AI-accelerated speed while gaining immediate visibility into the components and risks they assemble.
- Security teams: Faster remediation (a 59% decline in median unresolved age) shows progress, but the 4.31x increase in critical/high issues signals that detection and mitigation capacity must scale faster still. Security teams will face sustained pressure to shift left — to shape choices made at assembly rather than rely chiefly on post-build reviews.
- Procurement leaders: With application creation accelerating almost fivefold, procurement and acquisition decisions that accept post-development security reviews as sufficient may inadvertently acquire higher volumes of critical risk. Sonatype’s recommendations imply procurement practices should demand evidence of earlier, assembly-time security controls.
The report presents a clear tension: AI tools and practices are driving a dramatic rise in application output and, simultaneously, in critical and high-severity vulnerabilities. Organizations are shaving the time vulnerabilities remain open, but Sonatype’s data and commentary suggest those remediation gains have not kept pace with the rate at which new risk is introduced. The firm’s prescription — move security decisioning to the moment software is assembled — offers a specific operational pivot that both developers and security teams will have to test in practice.
Source: https://www.infosecurity-magazine.com/news/enterprise-apps-critical-high/




