TL;DR: Deadline pressure, late discovery, and remediation capacity gaps drive the behavior, with 81% of organizations knowingly shipping vulnerable code, according to Pixee citing Checkmarx survey data. The lesson for IAM and security programmes is that controls fail when teams cannot convert findings into timely fixes, especially as AI and secrets exposure increase the volume of work.
NHIMG editorial — based on content published by Pixee: 81% Ship Vulnerable Code. The Problem Isn't Negligence, It's Capacity
By the numbers:
- Eighty-one percent of organizations knowingly ship code with vulnerabilities, according to Checkmarx's 2026 Future of AppSec survey of over 1,500 CISOs, AppSec managers, and developers worldwide.
Questions worth separating out
Q: What breaks when vulnerability discovery outpaces remediation capacity?
A: When discovery moves faster than validation and patching, the backlog becomes the control failure.
Q: Why do deadline pressures increase security risk in AppSec and IAM programmes?
A: Deadline pressure pushes teams to optimise for delivery, not closure.
Q: What should executives measure to know remediation automation is working?
A: Executives should look at time to first action, mean time to remediate, and the share of critical issues closed within the agreed service level.
Practitioner guidance
- Measure remediation capacity, not just vulnerability count. Track how many findings each team can close per sprint, how long critical fixes wait in queue, and where validation bottlenecks appear.
- Prioritise fixes by blast radius and exploitability. Create a release rule that separates high-impact issues from background noise using environment context, authentication boundaries, and exposure path.
- Automate the repetitive part of remediation. Use scripted fixes, policy-as-code, and validation checks to shorten the time between finding and closure.
What's in the full article
Pixee's full blog post covers the operational detail this post intentionally leaves for the source:
- The specific survey framing behind the 81% finding and the surrounding response data from Checkmarx.
- The full breakdown of why teams ship vulnerable code, including deadline pressure and late discovery patterns.
- The remediation capacity argument in more detail, including how the article distinguishes triage from negligence.
- The related analysis links and resources that expand the AppSec backlog discussion into practical follow-up material.
👉 Read Pixee's analysis of why teams knowingly ship vulnerable code →
81% ship vulnerable code: what AppSec teams are missing?
Explore further
Capacity, not character, is the dominant control failure. The article's core argument is correct: teams often know vulnerabilities exist but cannot clear them fast enough. That is a systems problem, not a morality tale. In identity governance terms, the same pattern appears when access reviews, secret rotation, or offboarding queues outrun the people and automation assigned to them. The practical conclusion is simple: measure closure capacity, not just detection volume.
A question worth separating out:
Q: What should security teams do when they cannot fix everything they find?
A: They should rank work by exposure path, business impact, and exploitability, then define explicit acceptance rules for what can wait. If the team cannot say which issues are allowed to remain open and why, the backlog is functioning as unmanaged risk rather than controlled prioritisation.
👉 Read our full editorial: AppSec capacity limits, not negligence, drive vulnerable code shipping