Site navigation

APIs are Now the Single Most Exploited Attack Surface

Tom Quinn

,

API security
“API security is integral to successful AI adoption, and AI by its very nature has made the consequences of getting it wrong much larger and much more impactful,” said Ivan Novikov, Wallarm.

APIs have become attackers’ number‑one target, with adversaries exploiting repeatable failures in identity, access control, and exposed interfaces, often at machine speed and massive scale.

After analysing more than 67,000 published vulnerabilities from 2025, security platform Wallarm’s 2026 API ThreatStats Report found that 17%, slightly more than 11,000, were API-related, while a separate review of CISA’s 2025 KEV entries showed that 43% were linked to APIs, evidence that these have fast become attackers’ favourite target.

According to Wallarm, that’s because most of these API vulnerabilities are fast, remote, and easy to exploit. The report found 97% of API flaws could be exploited with a single request, while 98% were easy or trivial to exploit, and almost all (99%) were remotely exploitable.

Worse, Wallarm found that 786 of these API vulnerabilities overlapped with 2,185 AI-related flaws identified last year, meaning that more than a third of AI vulnerabilities involve APIs, a trend which persists across KEVs.

Added to that, the report warned that agentic AI has created a new security risk through the Model Context Protocol (MCP), basically a middle layer that allows AI models to engage with external services through a controlled interface, managing what the AI can see, request, or do.

Wallarm identified 315 MCP‑related issues in 2025, about 14% of all AI vulnerabilities, and the numbers are climbing fast. From Q2 to Q3 alone, the report found that MCP exploits spiked by 270%, and were tied to a major API breach that exposed thousands of servers. 

The report’s breach analysis reinforces the idea that AI is lowering the barrier to entry, with AI platforms and tools accounting for 15% of API breaches, including some of the most damaging attacks.

Wallarm found that more than half of API vulnerabilities were found to be exploitable by “script kiddies”, inexperienced attackers who rely on pre‑made scripts and automated exploit kits, but cautioned that the combination of high impact, mass-scale attacks with low skill hackers is what makes API risk uniquely persistent.  


Recommended reading


The study also shows a clear shift in tactics, with these attackers leaning more on logic abuse, trust failures and resource exhaustion than finding bugs, trend Wallarm said is most obvious in cross‑site issues and broken access control, which have become the most common attack types.

Injections, however, continue to hit hard, not because attackers prefer them, but because APIs still handle huge amounts of untrusted input at scale.

Wallarm said its findings show CISOs can’t afford to treat API security as “just an AppSec problem”, and should work to address identity, exposure, and abuse vulnerabilities before automation and scale turn familiar weaknesses into material business risk. 

“API security is at the heart of any AI transformation,” said Ivan Novikov, CEO at Wallarm. “Every AI application or agent interaction is mediated through an API. API security is integral to successful AI adoption, and AI by its very nature has made the consequences of getting it wrong much larger and much more impactful.”

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data