Veracode tested 100+ AI models writing code.
56% is the average security pass rate.
44% of AI-generated code contains OWASP Top 10 vulnerabilities.
Black Hat 2026 just proved it gets worse.
Researchers found critical flaws in Anthropic, Google, and OpenAI coding agents — all in their own default configurations.
One malicious GitHub issue.
That is all it took to trigger remote code execution on Anthropic's Claude Code.
Google's Gemini CLI got rated CVSS 10.0.
The flaw let attackers bypass execution restrictions, steal credentials, and compromise downstream supply chains.
OpenAI's Codex had a writable AGENTS.md file that persisted attacker instructions across automated workflow stages.
The bug is not in the model.
It is in the harness — the software around the model that manages tool access, permissions, and orchestration.
1Password tested 6,000 AI patches.
26% fully corrected the vulnerability.
The rest either missed the exploit path or introduced new problems.
CodeRabbit just raised $143M at $1.5B because every enterprise now needs a governance layer between AI agents and production.
If your CI/CD pipeline accepts AI-generated code without static analysis, secrets scanning, and human review — you are shipping vulnerabilities at machine speed.
Audit your DevSecOps pipeline today.
If AI touches your code, security must touch it first.
SOURCE: https://www.esecurityplanet.com/threats/veracode-finds-ai-generated-code-still-struggles-with-security/
VERIFIED: eSecurity Planet (Aug 12, 2026), eSecurity Planet Black Hat coverage (Aug 6, 2026), Reuters CodeRabbit funding (Aug 12, 2026)
SIGNAL: AI-generated code is flooding enterprise repos at scale. Security hasn't kept up. This is a $1.5B market signal.
AI coding agents just got caught with a CVSS 10.0. Your DevSecOps pipeline is not ready.
AI-Assisted Content — Produced with AI assistance and human editorial review.
Learn more
0 Comments