Vendor Capital Allocation β€” Q1 2026

πŸ¦… Vendor Capital Allocation Report β€” Q1 2026

Data snapshot: 2026-08-11  |  Financial data: Yahoo Finance TTM (trailing twelve months)

This report covers Q1 2026 β€” one quarter behind the Vendor Pain Index, to ensure all earnings are confirmed before drawing conclusions about how vendors spend their money.

✍️ From the Editor

As someone who regularly performs release testing and reads through hundreds of pages of vendor release notes, I kept running into the same frustrating phenomenon: witnessing the exact same system bug survive across 14 different firmware releases.

For a long time, I wondered about the root cause of this. Are we looking at a lack of engineering talent? Is it a failure in QA? Or is it simply a matter of shifting internal priorities?

I realized that looking at CVE counts and Bug IDs alone doesn't provide the full picture. By starting to correlate this technical debt with public financial data, we might be able to reduce this complex phenomenon to a much simpler question: Are these persistent technical flaws ultimately just a reflection of how a vendor manages its cash flow?

For network engineers and security admins who don't usually read Wall Street earnings reports, this brings us right back to the core question of this platform: Why should I care?

You should care because capital allocation is a proxy for engineering culture. If a vendor chooses to maximize short-term shareholder returns while starving R&D, the operational burden doesn't disappear β€” it is simply passed down to you. This report attempts to explore exactly that.


πŸ“Š At a Glance

5 Extractors  Β·  8 Builders  Β·  16 Balanced  Β·  1 Drifters


πŸ”’ Capital Allocation Quadrant

R&D Intensity = R&D Γ· Revenue Γ— 100  |  Shareholder Ratio = (Buybacks + Dividends) Γ· FCF Γ— 100  |  Thresholds: R&D β‰₯ 12.0% = engineering-focused Β· Shareholder β‰₯ 50% of FCF = shareholder-focused

#ArchetypeVendorTicker Revenue (TTM)R&D (TTM)R&D Intensity FCF (TTM)BuybacksDividendsShareholder Ratio
1πŸ’° ExtractorFortinetFTNT$7.5B$0.8B10.9%$3.1B$2.9Bβ€”91.7%
2πŸ’° ExtractorMicrosoftMSFT$331.8B$35.6B10.7%†$67.0B$22.3B$26.4B72.7%
3πŸ’° ExtractorAppleAAPL$466.8B$34.5B7.4%†$136.7B$82.2B$15.6B71.6%
4πŸ’° ExtractorJuniper/HPEHPQ$57.4B$1.6B2.8%$3.8B$1.1B$1.1B57.1%
5πŸ’° ExtractorDellDELL$134.0B$3.1B2.3%$9.4B$6.2B$1.5B82.3%
6πŸ—οΈ BuilderCrowdStrikeCRWD$5.1B$1.4B27.1%$1.4B$0.2Bβ€”12.6%
7πŸ—οΈ BuilderGitLabGTLB$1.0B$0.3B27.0%$0.3B$0.1Bβ€”19.2%
8πŸ—οΈ BuilderRapid7RPD$0.9B$0.2B22.1%$0.1Bβ€”β€”0.0%
9πŸ—οΈ BuilderOktaOKTA$3.0B$0.6B21.3%$0.9B$0.2Bβ€”27.8%
10πŸ—οΈ BuilderZscalerZS$3.2B$0.7B21.1%$0.9Bβ€”β€”0.0%
11πŸ—οΈ BuilderProgress SoftwarePRGS$1.0B$0.2B19.0%$0.3B$0.1B$0.0B35.5%
12πŸ—οΈ BuilderPalo Alto NetworksPANW$10.6B$2.0B18.7%$3.8Bβ€”β€”0.0%
13πŸ—οΈ BuilderOracleORCL$67.4B$10.3B15.2%$-23.7B ⁻$0.2B$5.8Bβ€” (neg. FCF)
14βš–οΈ BalancedAtlassianTEAM$6.6B$2.5B38.2%$1.2B$1.8Bβ€”βš οΈ 152.5%
15βš–οΈ BalancedSentinelOneS$1.1B$0.3B30.5%$0.0B$0.1Bβ€”βš οΈ 375.0%
16βš–οΈ BalancedMongoDBMDB$2.6B$0.7B27.7%$0.6B$0.5Bβ€”84.7%
17βš–οΈ BalancedElasticESTC$1.7B$0.5B25.9%$0.3B$0.2Bβ€”71.9%
18βš–οΈ BalancedTenableTENB$1.0B$0.2B21.2%$0.2B$0.3Bβ€”βš οΈ 140.0%
19βš–οΈ BalancedServiceNowNOW$14.7B$3.0B20.1%$4.6B$3.4Bβ€”74.6%
20βš–οΈ BalancedSAPSAP$38.2B$6.6B17.4%$8.7B$2.9B$2.9B66.2%
21βš–οΈ BalancedQualysQLYS$0.7B$0.1B17.1%$0.3B$0.2Bβ€”74.2%
22βš–οΈ BalancedZoomZM$4.9B$0.8B17.0%$2.0B$1.6Bβ€”79.6%
23βš–οΈ BalancedCheck PointCHKP$2.8B$0.5B16.7%$1.1B$1.4Bβ€”βš οΈ 127.3%
24βš–οΈ BalancedF5FFIV$3.3B$0.5B16.3%$1.0B$0.6Bβ€”64.9%
25βš–οΈ BalancedCiscoCSCO$60.8B$9.3B15.3%$11.8B$7.5B$6.5B⚠️ 119.2%
26βš–οΈ BalancedBroadcom/VMwareAVGO$75.5B$11.0B14.6%$32.8B$8.5B$11.8B61.9%
27βš–οΈ BalancedSalesforceCRM$42.8B$6.0B14.0%$14.7B$37.2B$1.6B⚠️ 264.4%
28βš–οΈ BalancedGoogleGOOGL$445.9B$61.1B13.7%†$53.3B$17.4B$10.3B52.0%
29βš–οΈ BalancedIBMIBM$69.1B$8.3B12.0%$13.1B$1.1B$6.3B56.0%
30πŸŒ€ DrifterHPEHPE$38.8B$2.5B6.5%$4.0B$0.4B$0.8B31.3%
Insufficient data: Amazon/AWS

† Hyperscaler scale note: At $300B+ revenue, even a "low" R&D intensity % represents tens of billions in absolute spend. Percentage-based comparison still holds (it measures reinvestment discipline relative to earnings power), but absolute context matters: Microsoft (MSFT): $35.6B R&D absolute Β· Apple (AAPL): $34.5B R&D absolute Β· Google (GOOGL): $61.1B R&D absolute. ⚠️ Leveraged: Shareholder Ratio >100% means the vendor is returning more capital than it generates β€” funded by debt or cash reserves. Not sustainable long-term.  |  ⁻ Negative FCF: Typically driven by large acquisitions or capex cycles; shareholder ratio excluded as meaningless.


πŸ—ΊοΈ The Four Archetypes

ArchetypeR&D IntensityShareholder RatioWhat it means
βš–οΈ Balancedβ‰₯ 12.0%β‰₯ 50% of FCFInvests heavily in engineering and rewards shareholders. Rare β€” only possible with strong margins.
πŸ—οΈ Builderβ‰₯ 12.0%< 50% of FCFReinvests aggressively in engineering. Quality-first, often a growth-stage company.
πŸ’° Extractor< 12.0%β‰₯ 50% of FCFReturns capital to shareholders while underinvesting in engineering. Raises questions about long-term quality.
πŸŒ€ Drifter< 12.0%< 50% of FCFNeither investing nor returning capital. Often signals strategic uncertainty or heavy M&A activity.

πŸ”— Why This Matters for Security

Capital allocation is not just a financial story. For enterprise IT and security professionals, it is a proxy for engineering culture.

A vendor classified as an Extractor β€” high shareholder returns, low R&D intensity β€” is making an active choice. They have the cash. They chose not to reinvest it in engineering. When that same vendor appears at the top of the Vendor Pain Index, the two data points tell a coherent story: the operational burden they create was an avoidable cost, not an inevitable one.

A Builder with a high CVE count deserves a different interpretation. Heavy R&D investment suggests growing attack surface from rapid development β€” a different quality problem than a vendor simply not caring.

Neither metric is a verdict. Both together are a better question.


πŸ“Ž Appendix β€” Raw Financial Data (TTM)

All values trailing twelve months (TTM). FCF = Operating Cash Flow (TTM) βˆ’ Capital Expenditure (TTM), computed from quarterly cashflow statements (last 4 quarters summed). Buybacks = Common Stock Payments TTM. Use the ticker links to verify directly on Yahoo Finance.

VendorTickerRevenue (TTM)R&D (TTM)Operating CF (TTM)Capex (TTM)FCF (TTM)Buybacks (TTM)Dividends (TTM)
Amazon/AWSAMZN$775.7Bβ€”$148.5B$151.00B$-2.5Bβ€”β€”
AppleAAPL$466.8B$34.5B$146.7B$10.04B$136.7B$82.2B$15.6B
AtlassianTEAM$6.6B$2.5B$1.2B$0.04B$1.2B$1.8Bβ€”
Broadcom/VMwareAVGO$75.5B$11.0B$33.6B$0.86B$32.8B$8.5B$11.8B
Check PointCHKP$2.8B$0.5B$1.1B$0.03B$1.1B$1.4Bβ€”
CiscoCSCO$60.8B$9.3B$13.0B$1.24B$11.8B$7.5B$6.5B
CrowdStrikeCRWD$5.1B$1.4B$1.8B$0.39B$1.4B$0.2Bβ€”
DellDELL$134.0B$3.1B$12.5B$3.03B$9.4B$6.2B$1.5B
ElasticESTC$1.7B$0.5B$0.3B$0.01B$0.3B$0.2Bβ€”
F5FFIV$3.3B$0.5B$1.1B$0.08B$1.0B$0.6Bβ€”
FortinetFTNT$7.5B$0.8B$3.4B$0.28B$3.1B$2.9Bβ€”
GitLabGTLB$1.0B$0.3B$0.3B$0.01B$0.3B$0.1Bβ€”
GoogleGOOGL$445.9B$61.1B$185.7B$132.40B$53.3B$17.4B$10.3B
HPEHPE$38.8B$2.5B$6.4B$2.37B$4.0B$0.4B$0.8B
IBMIBM$69.1B$8.3B$14.9B$1.74B$13.1B$1.1B$6.3B
Juniper/HPEHPQ$57.4B$1.6B$4.6B$0.81B$3.8B$1.1B$1.1B
MicrosoftMSFT$331.8B$35.6B$182.9B$115.95B$67.0B$22.3B$26.4B
MongoDBMDB$2.6B$0.7B$0.6B$0.01B$0.6B$0.5Bβ€”
OktaOKTA$3.0B$0.6B$0.9B$0.02B$0.9B$0.2Bβ€”
OracleORCL$67.4B$10.3B$32.0B$55.66B$-23.7B$0.2B$5.8B
Palo Alto NetworksPANW$10.6B$2.0B$4.2B$0.42B$3.8Bβ€”β€”
Progress SoftwarePRGS$1.0B$0.2B$0.3B$0.01B$0.3B$0.1B$0.0B
QualysQLYS$0.7B$0.1B$0.3B$0.01B$0.3B$0.2Bβ€”
Rapid7RPD$0.9B$0.2B$0.2B$0.03B$0.1Bβ€”β€”
SAPSAP$38.2B$6.6B$9.5B$0.73B$8.7B$2.9B$2.9B
SalesforceCRM$42.8B$6.0B$15.2B$0.56B$14.7B$37.2B$1.6B
SentinelOneS$1.1B$0.3B$0.1B$0.03B$0.0B$0.1Bβ€”
ServiceNowNOW$14.7B$3.0B$5.3B$0.74B$4.6B$3.4Bβ€”
TenableTENB$1.0B$0.2B$0.3B$0.02B$0.2B$0.3Bβ€”
ZoomZM$4.9B$0.8B$2.0B$0.06B$2.0B$1.6Bβ€”
ZscalerZS$3.2B$0.7B$1.1B$0.21B$0.9Bβ€”β€”

πŸ“š Methodology

  • Data source: Yahoo Finance via yfinance β€” TTM (trailing twelve months) values as of 2026-08-11. TTM ensures comparability across vendors with different fiscal year-ends.
  • R&D Intensity: R&D Spend Γ· Revenue Γ— 100. Measures what fraction of revenue a vendor reinvests in engineering. The enterprise tech sector average is approximately 12–15%.
  • Shareholder Ratio: (Buybacks + Dividends) Γ· Free Cash Flow Γ— 100. Measures what fraction of generated cash is returned to shareholders rather than reinvested. Values above 100% indicate a vendor is borrowing to fund returns.
  • Free Cash Flow (FCF): FCF = Operating Cash Flow (TTM) βˆ’ Capital Expenditure (TTM). Both values are sourced from Yahoo Finance quarterly cashflow statements β€” we sum the four most recent quarters to compute true TTM, not the fiscal year value. This distinction matters: yfinance's freeCashflow field sometimes returns the most recent fiscal year rather than TTM, which can diverge significantly for companies mid-fiscal-year. We compute FCF directly from quarterly Operating Cash Flow and Capital Expenditure to avoid this bias.
  • Buybacks: "Common Stock Payments" (TTM) from the quarterly cashflow statement β€” the cash actually paid to repurchase shares, summed over four quarters.
  • Dividends: "Cash Dividends Paid" (TTM) from the quarterly cashflow statement where disclosed. Many security-focused vendors pay no dividends.
  • Buybacks and Dividends: From the most recent TTM cashflow statement. Buybacks sourced from share repurchase line items; dividends from cash dividends paid.
  • Thresholds: R&D Intensity β‰₯ 12.0% = engineering-focused. Shareholder Ratio β‰₯ 50% = shareholder-focused. These are calibrated to the enterprise software and security sector and will be reviewed quarterly.
  • Quarter offset: This report covers Q1 2026 β€” one quarter behind the current Vendor Pain Index. Financial data requires confirmed earnings reports; we do not publish estimates.
  • Private vendors are excluded β€” financial data is not publicly available without a stock listing.

Data: Yahoo Finance (snapshot 2026-08-11)  Β·  Companion report: Why Should I Care? β€” Vendor Pain Index
πŸ¦… Built by an engineer who got tired of reading 200 security alerts a day and asking why the same vendors kept showing up.

Read more

Why Should I Care? β€” 2026-09-24 | πŸ”΄ 0 HIGH Β· 🟑 0 MEDIUM Β· πŸ”΅ 27 RADAR Β· βšͺ 69 FILTERED

πŸ“‹ Briefing β€” 2026-09-24 27 vendor intel items scanned Β |Β  πŸ”΄ 0 HIGH Β |Β  🟑 0 MEDIUM Β |Β  πŸ”΅ 27 RADAR Β |Β  βšͺ 69 FILTERED βœ… No critical items today. Everything else can wait. πŸ”΅ 15 items on the radar β€” see below ↓ Why Should I Care? πŸ”΄ HIGH β€” Handle Now No HIGH priority items in the last 24h. Why Should I Care? 🟑 MEDIUM

By Josip Sokolovic

Why Should I Care? β€” 2026-09-23 | πŸ”΄ 5 HIGH Β· 🟑 3 MEDIUM Β· πŸ”΅ 27 RADAR Β· βšͺ 69 FILTERED

πŸ“‹ Briefing β€” 2026-09-23 35 vendor intel items scanned Β |Β  πŸ”΄ 5 HIGH Β |Β  🟑 3 MEDIUM Β |Β  πŸ”΅ 27 RADAR Β |Β  βšͺ 69 FILTERED πŸ”΄ Critical β€” action required: 1. CISA Adds Four Known Exploited Vulnerabilities to Catalog (CVE-2026-85102, CVE-2026-93616, CVE-2026-93952, CVE-2026-94127) β€” Yes, if you run any affected versions of Check Point, Arista VeloCloud Orchestrator, or F5 BIG-IP APM: these vulnerabilities

By Josip Sokolovic

Why Should I Care? β€” 2026-09-22 | πŸ”΄ 1 HIGH Β· 🟑 0 MEDIUM Β· πŸ”΅ 17 RADAR Β· βšͺ 66 FILTERED

πŸ“‹ Briefing β€” 2026-09-22 18 vendor intel items scanned Β |Β  πŸ”΄ 1 HIGH Β |Β  🟑 0 MEDIUM Β |Β  πŸ”΅ 17 RADAR Β |Β  βšͺ 66 FILTERED πŸ”΄ Critical β€” action required: 1. CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2026-7273) β€” Yes, if you run Zyxel GS1900 Series Switches: This vulnerability can allow attackers to take full control of your switch. Everything else

By Josip Sokolovic

Why Should I Care? β€” 2026-09-21 | πŸ”΄ 23 HIGH Β· 🟑 32 MEDIUM Β· πŸ”΅ 209 RADAR Β· βšͺ 73 FILTERED

πŸ“‹ Briefing β€” 2026-09-21 264 vendor intel items scanned Β |Β  πŸ”΄ 23 HIGH Β |Β  🟑 32 MEDIUM Β |Β  πŸ”΅ 209 RADAR Β |Β  βšͺ 73 FILTERED πŸ”΄ Critical β€” action required: 1. CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2026-76461) β€” Yes, if you run Cisco Secure Email Gateway versions 12.0.0 - 12.0.4: SQL injection vulnerability, actively exploited in

By Josip Sokolovic