OWASP Top 10
OWASP Top 10:2025 is the current list. There is no 2026 edition. Access control still leads, misconfiguration is second, and supply chain failures and exceptional-condition handling were added in 2025.
OWASP Top 10 index
- A01 Broken Access Control - OWASP Top 10:2025 rank 1, still the most serious category. Covers IDOR, missing function-level checks, forced browsing, tenant bypass, and SSRF, which moved here from its own 2021 slot. OWASP's contributed data put one or more of 40 mapped CWEs in about 3.73% of tested applications.
- A02 Security Misconfiguration - Moved from 5th in 2021 to 2nd in 2025. Default configs, open admin and debug surfaces, loose CORS, missing headers, public object storage, and unnecessary features. OWASP reported about 3.00% of tested applications had one or more of 16 CWEs here, and attributes the rise to configuration-driven software.
- A03 Software Supply Chain Failures - New in 2025 as an expansion of 2021's vulnerable-and-outdated-components category. Covers dependencies plus the systems that build, store, and ship software: CI, registries, and update channels. OWASP says it has few occurrences in the contributed data (5 CWEs) and the highest average exploit and impact scores from CVEs, and it led the community survey.
- A04 Cryptographic Failures - Was 2nd in 2021 and is 4th in 2025. Cleartext transport, weak password storage, hardcoded keys, and tokens that are only encoded. OWASP reported about 3.80% of applications had one or more of 32 CWEs in this category. Exposure of sensitive data is the usual outcome, not a cipher puzzle.
- A05 Injection - Was 3rd in 2021 and is 5th in 2025, still one of the most tested classes. OWASP maps 38 CWEs and the largest associated CVE count. The category runs from frequent, often lower-impact XSS to less frequent, higher-impact SQL injection. Name the interpreter before you name the bug.
- A06 Insecure Design - Was 4th in 2021. Missing limits, unsafe workflows, and trust assumptions that correct syntax will not fix. This is where business logic, step skipping, and client-trusted prices live.
- A07 Authentication Failures - 2025 shortens the 2021 name 'Identification and Authentication Failures'. Session issuance, reset, MFA, and logout. The question is whether the server binds the next session to the person who proved identity.
- A08 Software or Data Integrity Failures - Unsigned updates, insecure deserialization, and CI or dependency paths that accept code or data without an integrity check. Sibling to supply chain failures: this slot is the missing check, A03 is the ecosystem around it.
- A09 Security Logging and Alerting Failures - 2025 renames the 2021 monitoring category to stress alerting, not only log lines. Hard to prove from outside. Note where a sensitive action gives the defender no signal, and where user input is written into logs that another system renders.
- A10 Mishandling of Exceptional Conditions - New in 2025, replacing SSRF's old slot (SSRF now sits under broken access control). OWASP maps 24 CWEs around improper error handling, failing open, and logic errors that appear only on abnormal conditions: timeouts, partial writes, parser failures, and conflicting headers.