Report · 2026
State of Our Findings 2026
An anonymised, aggregate look at what 21 PXL Security engagements and 190 findings actually turned up: the severity mix, the most common root causes and where the serious risk sat. Free to download, no form.
Free. No form, no email required.
Severity
How serious the findings were
Percentages are of the 180 findings rated on a CVSS scale; 10 red-team findings reported as narrative risk rather than a CVSS score are counted in the 190 total but excluded from this split rather than guessed at.
Root causes
What we find most often
Each percentage is the share of the 21 engagements in which that finding class appeared at least once, not a share of individual findings; the full list of 11 classes is in the report.
Key themes
What the data says
Hygiene recurs, clever bugs do not
The classes that appear most often are configuration and hygiene issues: information disclosure, security misconfiguration and missing hardening show up in most engagements. Novel exploits were not what drove the headline findings.
Serious findings are the minority that matters
High and Critical findings make up about 17% of CVSS-rated findings, yet they are the ones that end engagements. The long tail of Low and Informational issues is where most of the volume sits; the serious findings were almost always the ones that needed a human to chain together.
Credentials, access control and Active Directory
The headline issues clustered around credential handling, access control and Active Directory hygiene. Broken access control, exposed secrets, AD relay and Kerberoasting appear in fewer engagements than misconfiguration, but carry far more impact, and two to three red-team engagements reached full domain compromise.
Clean results are evidence too
Not every engagement is a horror story, and the report records clean results as carefully as serious ones. In this dataset one external web application returned zero findings, and a large perimeter of roughly 80 hosts had no exploitable High or Critical issues, with seven headline CVEs proven non-exploitable.
Method
How we built it
Every figure comes from our own engagement records, anonymised to counts before analysis.
- Aggregates findings from 21 recent PXL Security engagements: web, API, mobile, internal, external, red-team and phishing work.
- Counts are taken verbatim from each engagement's own findings summary; nothing is modelled or inflated.
- Findings not rated on a CVSS scale (some red-team reports) are counted in the totals but left out of the severity split rather than guessed at.
- Finding classes are measured by the share of engagements in which each class appeared at least once.
- All data is anonymised to counts only: no client, system or personal data was used.
- The sample is modest; it is published because it is real, not because it is large.
FAQ
Questions we're often asked
Do I need to fill in a form to download the report?
No. The PDF is a free, direct download with no form and no email address required.
Where does the data come from?
Every number comes from a delivered PXL Security engagement report. Counts are taken verbatim from each engagement's own findings summary, across web, API, mobile, internal, external, red-team and phishing work. Nothing is modelled or inflated.
How was the data anonymised?
The data was reduced to counts only before any analysis. No client names, systems or personal data were used, and the report contains no detail that identifies an organisation.
Will there be another edition?
We intend to update the report as more engagements are delivered. Each edition will follow the same rule: only real, delivered findings, anonymised to counts.
Read the full report
The PDF covers the full breakdown, the method, and what to fix first.
Want to know how your estate compares?
Send a short description of your environment and goals. A senior tester, not a salesperson, will reply with questions, a proposed approach and a quote.