Barracuda’s Jesus Cordero-Guzman warns attackers chain small vulnerabilities together, and the average website has 20 of them waiting.
If you think your website is probably fine because nothing’s gone wrong yet, new research might change your mind. Barracuda has found that the average web application carries around 20 security vulnerabilities, any of which could let an attacker steal data, hijack accounts, or slip into systems they shouldn’t be anywhere near.
Researchers went through hundreds of Barracuda Application Security Insight scans collected over five months in 2026, and found that just seven categories of vulnerability account for roughly 90% of everything they detected. The biggest offender, at 25% of flaws, is what’s called information disclosure. That’s when an application accidentally reveals too much about its own structure, hidden pages, backend routes, internal services, giving attackers a head start on mapping out where the weak points are without setting off any alarms.
Close behind, at 23%, is brand impersonation and spoofing. These are the kinds of weaknesses that make it easier for someone to clone your website, pretend to be your business, and trick customers into handing over passwords or personal details.
Client-side attacks, things like cross-site scripting, make up 14% of the flaws found. This is where attackers exploit weaknesses in how a page displays or runs content, letting them run malicious scripts inside a user’s browser, steal session cookies, or trick people into clicking something they shouldn’t.
Data exposure sits at 10%, covering situations where sensitive information leaks out through webpages, APIs, logs, cookies or tracking scripts that weren’t locked down properly. The remaining categories, weak or missing encryption (6%), outdated software and insecure configurations (6%), and poor session or credential management (5%), round out the list.
“Web applications are a critical interface for organisations, from website storefronts to interactive interfaces for customers, partners and operations. Keeping them secure is essential,” said Jesus Cordero-Guzman, Director, Solution Architects AppSec, NetSec and XDR International at Barracuda. “An average of 20 vulnerabilities per application means attackers have multiple opportunities to probe, test and exploit weaknesses. While not every issue is critical on its own, attackers often chain together several low and medium risk vulnerabilities to expose sensitive information, steal credentials or gain unauthorised access. Organisations need a proactive, layered approach to application security that continuously identifies and addresses risks before they can be exploited.”
Why this hits differently for Australian SMEs
It’s easy to read a report like this and assume it’s mostly about big enterprise platforms. It isn’t. If your business runs a website with a contact form, a booking system, a customer login, or an online store, you’re carrying the same categories of risk, often with a lot less oversight watching for them.
The numbers back that up locally. Roughly seven in ten small businesses have a website, but only about a third check it for updates on a weekly basis. That gap, between having a website and actually maintaining it, is exactly where the kind of “basic oversights” Barracuda flags tend to creep in.
There’s also a real cost attached to getting this wrong. The average self-reported cost of cybercrime for Australian small businesses has climbed to around $49,600. For a lot of SMEs, that’s not a line item you can just absorb.
What Australian SMEs can actually do about it
You don’t need an enterprise security team to close most of this gap. The Australian Cyber Security Centre’s Essential Eight is the go to local framework, a set of eight prioritised mitigation strategies designed specifically with resource-constrained organisations in mind. For website security specifically, the ACSC’s guidance is blunt: secure your website login with multi-factor authentication or a strong password, and keep your systems and plugins updated regularly.
A few practical steps line up directly with what Barracuda’s research flagged:
Lock down login access. MFA on your website admin, hosting account and domain registrar closes off a huge share of unauthorised access attempts, and it takes minutes to set up.
Patch on a schedule, not when you remember. Outdated software and insecure configurations made up 6% of the vulnerabilities Barracuda found, and they’re some of the easiest to fix once you actually notice them.
Know what your site is revealing. Information disclosure was the single biggest category at 25%. A basic external scan can show you what an attacker would see first, hidden admin pages, exposed routes, unnecessary detail about your backend.
Understand your Privacy Act obligations. If your business is covered by the Privacy Act and a data breach involving your website is likely to cause serious harm, you’re required to notify both the affected individuals and the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme. Knowing this in advance, not after an incident, makes a real difference to how you respond.
Back up regularly and test the restore. It won’t stop a vulnerability being exploited, but it determines how bad the aftermath is if one is.
None of this requires a big budget or a dedicated security hire. It requires treating your website the way you’d treat any other part of the business that touches customer data and money, with regular checks, not a set-and-forget attitude.
Keep up to date with our stories on LinkedIn, Twitter, Facebook and Instagram.
