Stack Scout

SaaS Stocks at 15-Year Lows: Buying Opportunity or Value Trap?

software developer working on laptop computer - Person typing on a laptop computer keyboard.

Photo by Anton Ryazanov on Unsplash

The Common Belief

21%. That is how much the iShares software ETF (IGV) has fallen year-to-date through June 2026 — a drawdown that, by the measure of Michael Burry's SW50 analysis published on the Cassandra Unchained Substack, now exceeds the dot-com crash, the 2008 financial crisis, and the 2022 rate shock in relative terms against the S&P 500. According to Google News coverage of Burry's research, institutional positioning in software has dropped to just 22.8% of portfolios, against 99.3% in semiconductors. The market consensus narrative is tidy and confident: AI autonomous agents displace seat-based software revenue, productivity tools lose pricing power, therefore exit SaaS and concentrate in the hardware layer.

Clean narratives are useful until they stop being accurate.

Where It Breaks Down

The flaw in the "SaaSocalypse" thesis is treating every software category as equally exposed to AI displacement. As of June 22, 2026, Gartner forecasts global cybersecurity spending will reach $244.2 billion in 2026 — up 13.3% from 2025 — driven by AI-enabled threats and regulatory compliance requirements including NIS2, DORA, and SEC disclosure rules. Notably, Gartner's projection is more aggressive than IDC's 12.2% estimate for the same period. The same AI that supposedly kills SaaS seats is simultaneously multiplying the exploitable attack surface enterprises must defend, making security budget cuts operationally and politically untenable for most organizations.

Software vs. Cybersecurity: The AI Divergence (June 2026)+30%+15%0%-20%-21%IGV ETF(YTD stock)-44%Adobe(YTD stock)+31%Palo AltoRevenue YoY+13.3%Cyber BudgetGrowth 2026

Chart: Red bars show YTD stock/index performance through June 2026; green and blue bars show YoY growth metrics. Sources: iShares, company filings, Gartner.

The divergence at the company level is sharp. Palo Alto Networks reported Q3 2026 revenue of $3.0 billion — up 31% year-over-year — and completed its $25 billion acquisition of CyberArk to lock in identity security as a platform capability, reaching a $205 billion market cap. The company's CEO captured the underlying dynamic precisely: "When AI agents log in at machine speed, logging becomes primary attack vector" — a shift from human-paced to autonomous threat patterns that favors comprehensive platform vendors over point solutions. Zscaler crossed $100 million in AI Protect bookings on a trailing-12-month basis, serving 9,400 enterprise customers across 160 data centers, though it carries negative $200 million in owner earnings (free cash flow adjusted for capital expenditure and growth spend) against $3.33 billion in revenue — revenue growth alone does not guarantee financial quality across this cohort.

On the productivity side, the counter-narrative centers on Adobe. As of June 18, 2026, the stock had fallen 44% year-to-date to $195.16, landing at a forward P/E of 8 and a PEG ratio (a valuation metric dividing the price-to-earnings multiple by the earnings growth rate — a figure below 1.0 is typically considered undervalued) of 0.53. Value investor Tobias Carlisle stated of the company: "I think the valuation's very compelling... a big discount and a lot of buybacks." The figure the market appears to be discounting: Adobe's Firefly AI credit consumption surged 45% quarter-over-quarter in Q1 2026, and AI-first ARR (annual recurring revenue from AI-powered features) exceeded $500 million, tripling year-over-year. Adobe holds 850 million monthly active users growing 17% year-over-year as of June 2026, with a $101 billion market cap. That is not a broken business model — it is a company in a narrative trough while its AI monetization ramps.

The broader threat context matters for operators, not just investors. As EDR Killers documented in its analysis of the Gentlemen Ransomware Group, sophisticated threat actors are already adapting techniques in response to AI-assisted endpoint detection — part of why cybersecurity budgets hold firm even as discretionary software spend contracts.

stock market chart declining financial data - A man holding a remote control in front of a computer

Photo by Jakub Żerdzicki on Unsplash

The Job Each Category Is Actually Hired to Do

The useful analytical cut is not "software versus AI" but "which specific job is at risk." Productivity software spans two fundamentally different jobs. The creation job — writing, designing, visual production — requires aesthetic judgment and brand context that generative AI augments rather than replaces outright at scale. The coordination job — scheduling, document routing, standard data entry, workflow handoffs — is precisely what Anthropic's Claude Cowork targets. Launched in April 2026, Claude Cowork competes directly with the coordination layer of tools like Microsoft 365, Notion, and workflow automation platforms, offering autonomous capabilities spanning CRM, project management, and finance. That displacement risk is real and near-term. The creative layer faces a different, slower-moving pressure.

Cybersecurity tools have no equivalent safe division. They are hired to do continuous threat surface reduction against adversaries who do not stop iterating. Anthropic's own Claude Mythos Preview, launched in early 2026, surpasses all but elite human hackers at finding software vulnerabilities — a disclosure that triggered Project Glasswing, a defensive coalition spanning CrowdStrike, Palo Alto Networks, Microsoft, Google, and NVIDIA. JPMorgan projects AI-security spending growing 3-4x faster than the broader market. The job cybersecurity vendors are hired to do just became materially harder and more expensive to execute well.

Michael Burry's "Castle/Chapel/Stone" framework from Cassandra Unchained is the right lens here. "Castle" moats — network effects, switching costs, distribution dominance — survive AI disruption; notably, Burry opened a new Microsoft position in Q1 2026 and doubled overall software exposure despite the sector-wide selloff, signaling conviction in platforms with defensible moats. "Stone" exposure — where core function can be replicated by an autonomous agent at near-zero marginal cost — does not; the analysis specifically flags DocuSign as carrying acute e-signature displacement risk in this environment. Most productivity tools for teams fall somewhere in between. Most cybersecurity platforms are Castles: integrated stacks with regulatory certification requirements, multi-year contracts, and an adversarial threat environment where ripping out a working platform mid-contract is operationally dangerous.

The Switching Cost Reality

For small businesses evaluating where to rationalize software budget, switching cost analysis matters more than the macro narrative. Adobe Creative Cloud's lock-in is genuine — proprietary file formats (PSD, AI, INDD), embedded workflow integrations, and 850 million monthly active users mean migration to an AI-native alternative carries real retraining and file compatibility costs. The global productivity software market grew from $74.94 billion in 2025 to $86.86 billion in 2026 at a 15.9% CAGR, with cloud-based deployments representing 71.31% of market share as of June 2026. Enterprises are still signing contracts. The "demo is not the product" warning applies directly: best productivity tools for teams that look compelling in a 20-minute walkthrough may carry months of integration, training, and workflow redesign costs that never appear in the pricing table.

SaaS Capital reports SaaS valuations compressed to 22.7x revenue in Q1 2026 — for the first time ever trading at or below S&P 500 valuation multiples. Separately, iShares data shows software multiples hitting 3.8x ARR (annual recurring revenue), the lowest since 2011. The market has already priced in significant switching away from incumbents. The actual enterprise renewal data, as of this writing, does not confirm that level of attrition is occurring at the pace the multiples imply.

A Better Frame

For small business operators and remote teams, the practical read is not about stock picking. It is about where to direct software budget in an environment where AI disruption is real in some workflows and overhyped in others. Tools handling coordination tasks — scheduling, document routing, standard data entry — are genuinely at risk of AI agent displacement on a 12-to-24-month horizon. Tools handling creative work, complex security decisions, and compliance-sensitive workflows face a different and longer timeline. The team-size cliff matters here too: smaller teams with lighter coordination overhead have less to gain from AI-first workflow automation platforms than the pricing pitch implies.

On security: do not defer. JPMorgan's projection of AI-security spending growing 3-4x faster than the broader market reflects a threat environment that is accelerating, not stabilizing. Underinvesting in endpoint security or identity management right now, when AI agents can probe systems at machine speed, is a timing error with asymmetric downside.

In my analysis, the market is pricing AI almost exclusively as revenue destruction for software, while companies with demonstrated AI monetization — Adobe's $500 million AI-first ARR tripling year-over-year, Palo Alto's 31% revenue growth off a $3.0 billion quarterly base — are being lumped in with genuinely disrupted names. The distinction between a value trap and a real dislocation opportunity is whether the underlying business is actually deteriorating or just the narrative around it. For names where the job-to-be-done remains defensible and AI monetization is already reflected in product metrics, the data does not yet support the severity of discount the market has applied.

Bottom line: Adopt incumbent productivity software where your team's switching cost genuinely exceeds the coordination efficiency gain AI agents deliver today — not in the demo, but in production. Prioritize security investment without delay. Wait on committing to AI-first coordination platforms until pricing stabilizes beyond introductory tiers and real-world integration complexity becomes legible.

Disclaimer: This article is editorial commentary for informational purposes only and does not constitute financial or investment advice. Tool features, pricing, and company performance metrics may change. Always verify current details with official sources. Research based on publicly available sources current as of June 22, 2026.