PXL Security LTD, Sofia, Bulgaria Offensive security since 2014[email protected]

Report · 2026

State of Our Findings 2026

An anonymised, aggregate look at what 21 PXL Security engagements and 190 findings actually turned up: the severity mix, the most common root causes and where the serious risk sat. Free to download, no form.

Free. No form, no email required.

21anonymised engagements
190findings delivered
7 of 21engagements had a High or Critical finding by CVSS rating
17%of CVSS-rated findings were High or Critical (31 of 180)
76%of engagements had at least one information disclosure finding

Severity

How serious the findings were

Percentages are of the 180 findings rated on a CVSS scale; 10 red-team findings reported as narrative risk rather than a CVSS score are counted in the 190 total but excluded from this split rather than guessed at.

Critical5 3%
High26 14%
Medium50 28%
Low80 44%
Informational19 11%

Root causes

What we find most often

Each percentage is the share of the 21 engagements in which that finding class appeared at least once, not a share of individual findings; the full list of 11 classes is in the report.

Information disclosure76%
Security misconfiguration57%
Missing security headers52%
Unpatched / EOL components43%
Broken access control38%
Authentication weaknesses38%
Weak cryptography33%

Key themes

What the data says

  • Hygiene recurs, clever bugs do not

    The classes that appear most often are configuration and hygiene issues: information disclosure, security misconfiguration and missing hardening show up in most engagements. Novel exploits were not what drove the headline findings.

  • Serious findings are the minority that matters

    High and Critical findings make up about 17% of CVSS-rated findings, yet they are the ones that end engagements. The long tail of Low and Informational issues is where most of the volume sits; the serious findings were almost always the ones that needed a human to chain together.

  • Credentials, access control and Active Directory

    The headline issues clustered around credential handling, access control and Active Directory hygiene. Broken access control, exposed secrets, AD relay and Kerberoasting appear in fewer engagements than misconfiguration, but carry far more impact, and two to three red-team engagements reached full domain compromise.

  • Clean results are evidence too

    Not every engagement is a horror story, and the report records clean results as carefully as serious ones. In this dataset one external web application returned zero findings, and a large perimeter of roughly 80 hosts had no exploitable High or Critical issues, with seven headline CVEs proven non-exploitable.

Method

How we built it

Every figure comes from our own engagement records, anonymised to counts before analysis.

  • Aggregates findings from 21 recent PXL Security engagements: web, API, mobile, internal, external, red-team and phishing work.
  • Counts are taken verbatim from each engagement's own findings summary; nothing is modelled or inflated.
  • Findings not rated on a CVSS scale (some red-team reports) are counted in the totals but left out of the severity split rather than guessed at.
  • Finding classes are measured by the share of engagements in which each class appeared at least once.
  • All data is anonymised to counts only: no client, system or personal data was used.
  • The sample is modest; it is published because it is real, not because it is large.

FAQ

Questions we're often asked

Do I need to fill in a form to download the report?

No. The PDF is a free, direct download with no form and no email address required.

Where does the data come from?

Every number comes from a delivered PXL Security engagement report. Counts are taken verbatim from each engagement's own findings summary, across web, API, mobile, internal, external, red-team and phishing work. Nothing is modelled or inflated.

How was the data anonymised?

The data was reduced to counts only before any analysis. No client names, systems or personal data were used, and the report contains no detail that identifies an organisation.

Will there be another edition?

We intend to update the report as more engagements are delivered. Each edition will follow the same rule: only real, delivered findings, anonymised to counts.

Read the full report

The PDF covers the full breakdown, the method, and what to fix first.

Want to know how your estate compares?

Send a short description of your environment and goals. A senior tester, not a salesperson, will reply with questions, a proposed approach and a quote.

Scoping details

Optional — helps us scope faster.

Prefer email? Write to [email protected]. We usually reply within one business day.