Seventy-seven percent of surveyed organizations experienced a software supply chain incident in the twelve months before Omdia ran its 2026 survey, per a research report Docker sponsored and published August 4. For teams still hardening pipelines, that sets the base rate: assume an attempt will land in the next year, and staff for it.

The most common attack shape has not changed. Exploits against known vulnerabilities in third-party software were the top category at 38 percent. What has shifted is what respondents fear next. AI technology is now the top-ranked supply chain risk at 40 percent, edging past third-party and open-source code (39 percent) and software dependencies (38 percent). The consequences respondents reported: 46 percent saw unauthorized access to applications and data, 37 percent had SLAs impacted during remediation, and 35 percent had developer credentials, secrets or keys stolen. On code composition, 38 percent of organizations say more than half of their code already comes from third-party sources, and Omdia projects that share to hit 58 percent within twelve months.

The tool table rewards the sponsor's category

The effectiveness ranking has one clear winner. Fifty-one percent of respondents rated secure containers as "very effective" for securing third-party and open-source components, the only category, out of eleven, where a majority landed in the top rating. Docker's blog post foregrounds that finding and points readers to Docker Hardened Images and Docker Scout. That is worth reading with the sponsor list in view: the category the sponsor sells topped a ranking the sponsor commissioned. Not disqualifying, but not the number you cite in a boardroom without a second source.