News · curated 20 Jul 2026
99.9% of fixable AI vulnerabilities remain unpatched
First reported helpnetsecurity.com
Coverage timeline
Single-source analysis — first reported, latest, and curated coincide.
Why it matters
Orca's findings highlight that production AI infrastructure — agent frameworks, RAG pipelines, and AI packages — is being deployed with vast unpatched attack surface, giving defenders a picture of systemic AI supply-chain risk.
Orca Security's 2026 State of AI Security Report, summarized by Help Net Security, finds 81.2% of companies running AI packages have at least one known vulnerability and 99.9% of AI vulnerability alerts with an available fix remain unpatched. The report describes attackers moving across five layers of the AI stack — package registries, model hubs, developer tools, agent frameworks, and brand trust — while organizations deploy agents, RAG pipelines, and vector databases with weak security hygiene.