OWASP LLM & Agentic Top 10 · 2025 to 2026

The codes stayed. The risks moved.

The OWASP Top 10 for LLM Applications ranks the risks that matter most when software calls a language model. All ten entries survived into 2026, but eight moved position and one was renamed, so a control mapped to a 2025 identifier may now point at the wrong risk.

2025 2026
Rose Fell Held Renamed

Select an entry for detail

Select any entry for its definition, both positions, and what changed inside it.

Positions verified against the OWASP Top 10 for LLM Applications 2026, v1.0. Scenario and citation counts are ours, taken from each entry's Example Attack Scenarios block, counting distinct inline references.

OWASP publishes its own rank migration figure on page 6 of that PDF; this restates it in a form you can link to and check. The four movement groupings are ours, derived from the published positions.

Built by CyberDesserts. Not affiliated with OWASP.