Build your future with us.

Enable continuous compliance with a unified, intelligent platform

Let's Discuss

OWASP Top 10 2025: Critical Updates Every CISO Must Know

The OWASP Top 10 2025 Release Candidate represents a fundamental shift in how we approach application security, moving beyond isolated code vulnerabilities to address systemic weaknesses across the entire software development lifecycle. With supply chain attacks escalating and software complexity at an all time high, security leaders must adapt their strategies to stay ahead.

The OWASP Foundation released the Top 10 2025 Release Candidate 1 (RC1) on November 6, 2025, at the Global AppSec Conference in Washington, DC. This update reflects the evolving threat landscape that security leaders face today, built on data from over 2.8 million applications contributed by organizations worldwide. For CISOs and cybersecurity professionals, understanding these changes is no longer optional, it’s essential for maintaining resilient security postures in an increasingly hostile digital environment.

What’s New: Two Categories That Demand Attention

The 2025 edition introduces two critical categories that reflect how modern applications are attacked:

Software Supply Chain Failures (A02:2025) emerges as a new standalone category, explicitly calling out malware in software ecosystems, compromised maintainers, and tampered build processes as leading threats. The reality is stark: these attacks rarely start in production. They begin on developer workstations, moving through CI systems, containers, and cloud environments often without triggering traditional security scanners. A single malicious dependency can compromise entire environments within hours.

Mishandling of Exceptional Conditions (A10:2025) addresses how systems fail when things go wrong. Poor error handling, logical flaws, and insecure failure states can expose sensitive data or create denial-of-service conditions. This category reinforces a critical principle: secure software isn’t only about preventing attacks, but also about failing safely and predictably.

The Top 10 at a Glance

Here’s the complete OWASP Top 10 2025 lineup:

  1. Broken Access Control – Maintains its #1 position with 3.73% of applications affected
  2. Security Misconfiguration – Jumped from #5 to #2, affecting 3.00% of tested applications
  3. Software Supply Chain Failures – New category addressing the growing supply chain threat
  4. Injection – Still a critical concern across SQL, NoSQL, OS commands, and more
  5. Insecure Design – Fundamental design flaws that can’t be fixed with code patches
  6. Security Logging and Monitoring Failures – Critical for incident detection and response
  7. Cryptographic Failures – Protecting data in transit and at rest remains paramount
  8. Identification and Authentication Failures – Weak authentication mechanisms continue to be exploited
  9. Vulnerable and Outdated Components – Known vulnerabilities in third-party components
  10. Mishandling of Exceptional Conditions – New category focused on safe failure modes

Why This Matters to Your Organization

The shift in OWASP’s focus reflects a harsh reality: the perimeter has moved. The supply chain has become the new attack surface, and traditional security controls often provide a false sense of security. Organizations must now consider:

  1. Visibility Across the Entire Development Lifecycle – You cannot secure what you cannot see. Modern applications are built from hundreds or thousands of dependencies, each representing a potential entry point for attackers.
  2. The Developer Workstation as Ground Zero – Compromised developer environments provide attackers with legitimate access to trusted systems. This is where supply chain attacks begin, making developer security non-negotiable.
  3. Systemic Over Symptomatic Fixes – The 2025 edition deliberately focuses on root causes rather than symptoms. This approach enables more effective remediation and better training outcomes for development teams.

Practical Steps for Security Leaders

Based on the OWASP Top 10 2025, here are immediate actions CISOs should consider:

  1. Audit Your Supply Chain Visibility – Do you know every component in your applications? Can you detect when a dependency is compromised? Implement automated software composition analysis and generate Software Bills of Materials (SBOMs) for all critical applications.
  2. Strengthen Developer Environment Security – Endpoint security for developers goes beyond traditional antivirus. Consider implementing package verification tools, dependency scanning before installation, and network segmentation for development environments.
  3. Revisit Your Configuration Management – With Security Misconfiguration jumping to #2, now is the time to audit cloud configurations, container images, and infrastructure-as-code templates. Implement automated configuration scanning in your CI/CD pipelines.
  4. Enhance Error Handling Standards – Review how your applications handle exceptions and failures. Implement logging that captures security-relevant events without exposing sensitive information. Ensure systems fail securely rather than failing open.
  5. Update Your Security Training – The expanded CWE mapping in the 2025 edition (averaging 25 CWEs per category) provides an opportunity to create targeted training programs for your development teams based on the languages and frameworks they use.

The Path Forward

The OWASP Top 10 2025 is designed as an awareness document, not a comprehensive security standard. Organizations seeking deeper security maturity should complement it with frameworks like OWASP’s SAMM (Software Assurance Maturity Model), ASVS (Application Security Verification Standard), or DSOMM (DevSecOps Maturity Model).

The community feedback period remains open until November 20, 2025, with the final version expected to follow shortly after. This presents an opportunity for security professionals to contribute their insights and help shape the final document.

Conclusion

The OWASP Top 10 2025 marks a pivotal shift in how we approach application security. The explicit recognition of supply chain threats and systemic vulnerabilities reflects the sophisticated attack patterns organizations face today. For security leaders, this isn’t just another compliance checklist; it’s a call to fundamentally rethink how we build, deploy, and maintain secure software.

The question isn’t whether your organization will adapt to these new realities, but how quickly you can implement the necessary changes before attackers exploit the gaps. The data from 2.8 million applications tells a clear story: these vulnerabilities are widespread, actively exploited, and require immediate attention.

The OWASP Top 10 2025 Release Candidate is available at owasp.org/Top10. Organizations are encouraged to review the detailed guidance for each category and begin implementing recommended controls.

For organizations seeking expert guidance on addressing OWASP Top 10 vulnerabilities through comprehensive audits, compliance readiness, or security consulting, specialized support can accelerate your security transformation journey.

Let us help you

By clicking on this button, you can connect with us. Let’s make your brand secure.

you may also like