News · curated 20 Jul 2026

99.9% of fixable AI vulnerabilities remain unpatched

Coverage timeline

13 Jul 2026helpnetsecurity.com

Single-source analysis — first reported, latest, and curated coincide.

Why it matters

Orca's findings highlight that production AI infrastructure — agent frameworks, RAG pipelines, and AI packages — is being deployed with vast unpatched attack surface, giving defenders a picture of systemic AI supply-chain risk.

Orca Security's 2026 State of AI Security Report, summarized by Help Net Security, finds 81.2% of companies running AI packages have at least one known vulnerability and 99.9% of AI vulnerability alerts with an available fix remain unpatched. The report describes attackers moving across five layers of the AI stack — package registries, model hubs, developer tools, agent frameworks, and brand trust — while organizations deploy agents, RAG pipelines, and vector databases with weak security hygiene.