State of Vulnerability Management 2026: What the Data Reveals
Evan Prowse of ActiveState joins Alan Shimel to break down the key findings from ActiveState’s second annual State of Vulnerability Management and Remediation Report. This special cloud-native edition dives deep into how organizations are building applications with containers, the real-world state of vulnerabilities in modern environments, and what remediation actually looks like in practice. The conversation also explores how AI is beginning to reshape vulnerability management, influencing both detection and remediation strategies—and what these shifts mean for security teams moving forward.
Transcript
Hey everyone. Welcome back here to Techstrong tv. Hi, I mean, happy to, uh, introduce my next guest to you.
His name is Evan Pros. Evan is a, uh, product marketing manager with Active State, and let's welcome him to Techstrong. Hey Evan, how's it going man?
Hey, Owen. Good. Thank you.
It's great to be here. Thanks for having us. It's good to have you on with us in active State.
Evan, I always like to give our audience a sense of who's, who they're listening to. So I said, you're a product marketing manager and a lot of people may say, oh, marketing, you know, bad word, but give, give people a sense of your journey, Evan, how, you know, how'd you get here? Definitely.
So, I mean, honestly, my interest in technology kind of goes way back to my university days. I went to a very technical university and was around, you know, a lot of software engineers and a lot of engineers in general. And I think that was the first time in my life I had that realization where you sort of understand why those things are cool and you want to get closer to them.
Uh, you know, I was studying psychology so way, way off from that. And so my objective was like, how can I find a way to get closer to the world of products and these things that I'm starting to be interested in? And I was doing some marketing work at the time and, uh, there was an opening at SAP for an internship, uh, to do product marketing.
And so I sort of got my foot in the door at SAP, you know, over a decade ago starting out in product marketing. And since then I've tried to really continue to be close to the product and technical world. Um, before my role here at ActiveState, I spent a bit of time at VMware and Broadcom working on the Tanzi division there.
And so I worked with Sure, um, application modernization technology specifically on the consulting team. And so we worked with a lot of customers to help them go and modernize legacy infrastructure, you know, move them from monolithic code to something like a cloud native development framework. And so, um, yeah, like you say, I've really been around technology for the greater part of my career.
And I would say too, you know, product marketing in particular, our job is to listen to the customer, is to understand what their problems are. And so I may be marketing, but I spent a lot of time chatting with the, uh, you know, world of DevSecOps and hearing firsthand sort of what they're experiencing in their day to day. Gotta ask you a question that's not a guitar neck I see behind you, is it?
It is, it is. Well, that makes you a bonafide tech dude. If you've got the guitar, guitar in the room with you.
I know. Are you, are you good? Can you play well or, or you just hack around?
You know, I'm kind of getting back into it. I play drums for most of my life, but, uh, drums are not the most conducive to a little apartment in Toronto. So, uh, no guitar's a bit more manageable for sure.
Yeah. So They're a lot more conducive now. And you can get drum pads electronic and just wear, uh, uh, EarPods or something, you know, earphones Totally, Totally Compared to banging skids.
But yes, it, it amazes me though, you know, as someone like me who, who speaks to a lot of people here on video like this, the amount of tech people who have guitars in their rooms, it, it might be approaching 50%. It's nuts. Yeah, I think I would agree with you.
I think going back to my time at VMware, you get on a call someone, and like you say, 50% of the time there's a wall somewhere in the back with, you know, at least a Couple. Yep. More than one even.
Anyway, good stuff, Evan. Let, let's talk active state, right? It's a, I've known about active state now for oh three or four years.
A good friend of mine was there a while ago, but I'm sure there are people out here in our audience who are not familiar with active state. How would you describe it to them? Yeah, definitely.
So, like you say, active space, active state has been working in the open source software space for actually a couple of decades now. And we really got our start way back helping organizations package and distribute open source languages. So namely, you know, legacy technologies like Pearl Tickle and Python for use in sort of more common enterprise applications, mainly porting them to Windows.
And so today I think, you know, a lot of people think of us as the Pearl Tickle and Python people, but a lot has changed over the years. Uh, of course infrastructure has evolved and so has teams need for open source in general. And so over the past couple of years, our focus has really been on taking that ability to build open source from source and extend it across all of the major language ecosystems.
So in doing so, we're tackling a lot of the complexity in things like solving complex dependency chains and ensuring that open source can build in a repeatable and predictable fashion for any o operating system. And sort of the, the result and what this, why this matters for customers is now we've developed a catalog of over 40 million built from source open source components. And in doing so, we're able to give customers access to these components.
And they know that they always will have the fewest amount of vulnerabilities possible, you know, it's safe from malicious code that might be injected somewhere in a supply chain attack. And we're always able to provide them the latest and greatest version of that open source. And so the great part about this catalog is customers can consume it in the way that makes the most sense for their business.
That could be simply, you know, mirroring the component into their package registry and using them like they would any piece of open source or that could be coming to us and saying, Hey, I need a container image with this software inside of it and I need it to be secure and updated for me on a continual basis. And so, you know, that story of container sort of relates to what we're talking about today. But really, I guess in short, you know, that's a lot of rambling.
Our goal is to help software development teams improve their security posture without slowing down the application teams as a result. Love it. Couple of questions follow up on that.
Look, AI's changing everything, uhhuh, especially AppSec, especially in open source. I guess maybe we could come into it when we talk about the report, but I wonder if AI has had any sort of, uh, impact on that. But even before we get to 11, just housekeeping for people who might be, want to go find out more about active state, where can they go?
No, the answer is very simple. com. Uh, specifically if you're looking for the report we're gonna chat about, we have a resources tab, you'll find it there.
No problem. Very cool. All right, let's talk about this report.
It's the 2026 state of vulnerability management and remediation report, container security edition. Um, what do you, what do we get in our hands around here, Evan? Yeah, absolutely.
So, uh, we started doing this report annually a couple of years ago. And the first iterations were really about asking, you know, our customers and the community at large about how they are dealing with open source vulnerabilities. You know, their ability to sort of go and remediate them and the trends they sort of see going forward for the future of this.
Um, obviously we've been talking with a lot of customers over the past couple years and containers, as we know, were sort of the prevailing infrastructure for teams to start deploying applications. And so we said, let's go and ask these same questions from a container point of view. And so, um, last year we interviewed 250 DevSecOps professionals.
So you can think titles like, you know, application security, uh, very true DevOps and platform engineering titles as well as a lot of engineering leaders. And we, we sort of ask them the same things like, how are you managing vulnerabilities in your container images? Is this something you're able to scale and keep up with on an ongoing basis?
What are the key challenges you're facing going forward? But also, you know, on a more positive note, we ask them where do they see advantages, uh, going forward in the future to solve this problem? What are they looking forward to, uh, exploring in 2026 when it comes to vulnerability management?
Very cool. Um, you know, I love when you've done a report kind of couple years, so you build up like sort of a body of knowledge. 'cause it gives you, you know, with that Monday morning quarterback kind of view, right, where you could look across years and see trends that build not just over the course of a year, but over the course of years.
Um, but let, let's focus in on this, this, uh, year's report. Evan, what if I asked you, Hey ev what were the three key takeaways from the report? How would you answer me?
Definitely, so I think the most striking thing for me was, um, of all of the people we interviewed for this report, 100% of them said in some capacity, containers are critical to their production workloads. So, you know, maybe that's not surprising given the audience, but every single person we talked with said, containers are something I am invested in and I'm interested in. And, you know, stand alone on that stat, it's not particularly interesting.
But I think what what makes it really striking is we also ask them how likely is it that you've experienced some form of container related security incident or breach over the past 12 months? And of that same set of people, 82% of them said they think they have likely experienced some issue in that timeframe. And so when you compare, you know, the number of a hundred percent of adoption versus 82% security incident, you really have to think like, what is going on here?
Um, you know, it's pretty clear containers have become basically near universally adopted, but are we keeping pace with the security measures that we need to put in place to solve that? Are we able to even tackle this problem? And so I think we knew this was a problem, but seeing that 82% number was something that really kind of stuck out to me as, wow, this is a bigger problem than we might think.
So that, that is sort of the foundation for all of this. The second thing I thought was really interesting is, um, we also ask companies, you know, how likely as a result of these vulnerabilities in your containers have you potentially run into an issue with a compliance audit or some sort of governance issue? And again, 78% of organizations said they think they've probably likely failed a compliance audit in that same timeframe.
And so you start to see this story go through of, you know, containers are important, we're not able to keep up with the vulnerabilities in them. And the outcome of that is that, you know, audits are failing. CVEs are, you know, super prevalent with inside their own environments and the, you know, the outcomes of that are kind of crazy.
You think about, um, you know, the potential penalties of an audit failure, maybe that's financial, maybe that's reputational. And so just sort of that combination of the through line is, is quite shocking. And then I think the sort of final thing that's kind of crazy to that me is that, um, when we asked why do they think this is happening, um, you know, what's causing this, A huge proportion of them cited visibility into their container images as sort of the root cause of this.
And I think, you know, if you think over the past few years things like SBOs and scanners have been talked about, you know, endlessly and teams have spent time implementing these into their pipelines. But the takeaway here is sort of even though we have this sort of surface level visibility from the tooling, the outputs of that tooling isn't really giving anyone any meaningful outputs. Yeah.
And, and, and it's, it's, it's literally you use the word surface, it's the surface. It's not very deep. Yeah.
You know, I think this is why Evan, we've seen like companies like, so for instance mm-hmm. Right? Come out with their own, um, like for their suse enterprise Linux or whatever they call it, right?
They, they have their own certified packages that are hardened to check for security. We're seeing, uh, who SUSE had bought that company, oh, I forget the name of the company. It's their cloud native company Rancher.
Right? Right. They're, they're doing a similar thing via rancher with like hardened certified containers that are what they say they are.
And SUSE is going to vouch for the security. It's not just suse. A lot of companies are are now trying to say, Hey, we'll, we'll we'll stand behind the container image you got from me.
The problem though, quite frankly is sometimes you're trading that open source freedom, Right. To get locked in to a particular vendor's, you know, distro or what have you. And um, and I don't know if people are comfortable doing that, in all honesty, right?
They, they people want freedom. Um, but on the other hand, you know, the container, I mean there's just a, as you said, we don't really, you know, we could scan containers the same way we scan other infrastructure doesn't mean we remediate it. Right?
And even if we're scanning it, it's only as good as what that scanner knows today, not what zero day or new vulnerability comes out tomorrow. Yes. Um, let me ask you another question.
Yeah. Anything in the report that kind of made your eyes pop open and say, whoa, I didn't see that coming? Yeah, I mean, I would say there's sort of two things that I thought were super interesting actually, just going back to what you talked about, about, um, good.
A lot of organizations are going and trying to build this model where they're saying, Hey, use our standard source for like you say, container images or whatever output may be. And we actually did ask a question which was, how much do you trust, you know, we use the language curated catalog, um, to effectively that's a fair word. Yeah.
Effectively mean the same thing. And 77% of uh, you know, are the respondents said they do trust this model versus say, going out to the open internet and pulling, you know, an artifact. But what's really interesting is we also asked them like, how frequently is your team actually just going to the open internet anyways in sort of pulling from, you know, whether it's Docker hub or one of the language repositories.
And 90% of them said, oh, well that's actually still what we're doing. And so I think to your point, there's a lot of interest in this model of, um, how do we go and get secure open source from a vendor? But you know, either people aren't finding what they're looking for, the convenience of going to, you know, the open internet is still sort of prevailing.
And uh, I mean I think for us at Active State, that's great to know considering we're sort of on a mission to go and rebuild as much open source as we can and kind of cross ecosystems. So that's one thing I think is just that sort of disconnect between, uh, intention and reality. And then the second is on ai.
Of course, you know, we probably can't escape any one of these interviews you do without talking about ai. But, um, one of the interesting positives, uh, from the report as well is that a huge amount of people kind of said they believe that AI is going to be one of the technologies that sort of is the tipping point to solving this problem of remediation. They expect that, you know, whether it's through automation or through some form of AI vulnerability management, this is something they're looking to invest in going forward.
And this surprised me, not because, you know, we know AI is popular, but just the idea of it being so close to your code base or, you know, touching potentially Cody wrote, I thought this was an interesting statistic as well. It is because, you know, you must had a lot of optimists in your survey, right? Yeah.
Because a lot of people say, oh no, AI's gonna make it worse. Right? Right.
Because the, the bad guys are using AI and you know, we don't know what's going on there and we automate, we go faster and we take humans out of the loop and, you know, AI is less secure. But I'm glad to see that so many folks actually think it is gonna help. 'cause I I'm in that camp, I think, you know, I don't think it's gonna be nirvana from day one, but I do think over time we're going to see it really helping out here.
Right. And I, I, well, I'm an optimist too. com under resources and it should be there.
Yeah, absolutely. I think that's the easiest way. com, you can hover over the resources tab and I believe it's right there.
So, um, yeah, I think very cool, easy way to find it. Yep. And you know, I I I wanna leave people with this again, I wanna return to active State in their mission, right?
Yeah. Give it to 'em again, if you don't mind. For sure.
So I think, like you said, you know, people are looking for a place to find secure, open source. They don't want to have to deal with the vulnerability challenges that come along with open source. As we know, everyone's got endless amounts of it in their stack today.
And really what we're doing at ActiveState is building a secure and trusted source for as much open source as we possibly can. So, like I said, we've amassed a catalog of over 40 million open source components that spans every major Lang language ecosystem. So think Python, Java, JavaScript, and teams can come to us and effectively plug right into that catalog that could be getting those packages to replace the ones they're pulling from places like Pi Pi or NPM or like, you know, in terms of this report.
They can come to us and say, I need a container image that's minimal, that's secure and only has the exact pieces of software inside that I need. So really our objective is to give people access to open source they know is free from vulnerabilities, is, you know, built by a trusted source in a hardened environment. And that is flexible enough for them to use without having to go and say, Hey, development team, like retool the entire way you're working, put new tools in place.
That's not how we operate. We're simply slotting into what teams are doing today. I love it.
Evan, thanks for coming here on Tech Truck tv, man. I appreciate it. Good report here with this, uh, 2026 edition.
Come back and keep us posted about what happens at Active State. Of course. Thanks for having me.
Appreciate it. My pleasure. Evan Pros, product manager, product marketing manager, excuse me, for active state here on Tech Trunk tv.
We're gonna take a break. We'll be back with more.