Vulnerabilities in Russian code jump 70% as Python and Java lead the risk ranking

Vulnerabilities in Russian code jump 70% as Python and Java lead the risk ranking

Russian cybersecurity firm AppSec Solutions has released client analytics from its AppSec.Hub platform, revealing a sharp increase in software vulnerabilities found in code produced by domestic IT companies, fintech firms, and industrial enterprises. The platform processed 550 million lines of code as of May 2026 and identified 3.1 million vulnerabilities — a 70% year-over-year increase. Despite the surge, the backlog of unpatched flaws has remained stable, suggesting that development teams are not scaling up their remediation efforts at the same pace.

The primary driver behind the growth is the rising volume of code submitted for analysis. The study draws on anonymized data from 4,214 codebases totaling approximately 510 million lines of code, covering the period from January 2025 to May 2026. The code profiles range from mobile and web applications built on common stacks (Java, Python, C#, JavaScript) to large enterprise systems and system-level code written in C and C++.

Python, Java, PHP, and C# top the list of programming languages with the highest number of detected vulnerabilities. The company attributes part of the problem to "vibe coding" — a trend where developers use AI-powered code generators without rigorous quality assurance, inadvertently introducing security flaws that often go unfixed due to time pressure or lack of awareness.

The findings highlight a growing gap between the speed of code production and the capacity for secure development practices in the Russian tech sector.

Tags: Security
Slate (Sl8) — the new social network. Post, grow your audience and earn — plus staking rewards that actually pay.
Invite codehXA6hX
Join Slate