HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

99.9% of Fixable AI Vulnerabilities Remain Unpatched, Exposing Cloud AI Deployments to Exploitation

Orca Security’s 2026 AI Security Report reveals that 81% of AI‑using firms have known flaws and that 99.9% of fixable alerts stay unpatched, creating a compliance gap for SOC 2 controls. Continuous evidence of patching is now a must‑have for audit readiness.

LiveThreat™ Intelligence · 📅 July 13, 2026· 📰 helpnetsecurity.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
3 recommended
📰
Source
helpnetsecurity.com

99.9% of Fixable AI Vulnerabilities Remain Unpatched, Exposing Cloud AI Deployments to Exploitation

What Happened — Orca Security’s 2026 State of AI Security Report found that 81.2 % of organizations running AI workloads have at least one known vulnerability and that 99.9 % of fixable AI‑related alerts remain unpatched. The study also highlighted low adoption of customer‑managed encryption keys and the proliferation of non‑human agent identities that broaden the attack surface.

Why It Matters for Compliance & Audit Readiness

  • Unpatched vulnerabilities directly violate SOC 2 CC6.1 (System Operations) and CC7.1 (Change Management) requirements for timely remediation of known security flaws.
  • The lack of continuous evidence that patches have been applied makes it difficult to demonstrate a defensible audit trail to examiners.
  • Mapping AI‑specific assets to control frameworks and automating patch verification provides the continuous‑compliance evidence that SOC 2 auditors expect.

Who Is Affected – Cloud‑native technology firms, SaaS providers, and any organization that embeds AI models, agent frameworks, or vector databases into production workloads.

Recommended Actions

  • Create an inventory of all AI packages, agent frameworks, and model‑hosting services.
  • Map each AI component to SOC 2 control requirements (CC6.1, CC7.1, CC5.1).
  • Deploy automated patch‑management tooling that captures immutable evidence of remediation for audit purposes.
  • Enable customer‑managed encryption keys for AI services where available.
  • Incorporate AI‑specific risk items into your continuous‑monitoring dashboard. Source: Help Net Security

Technical Notes

  • Attack surface expands across five AI‑stack layers: package registries, model hubs, developer tools, agent frameworks, and brand‑trust services.
  • 74.1 % of surveyed firms host at least one critical CVE in their AI packages, many of which are older than five years.
  • Lack of encryption‑key management (87‑98 % of firms) adds data‑confidentiality risk. Source: same article
📰 Original Source
https://www.helpnetsecurity.com/2026/07/13/ai-infrastructure-security-risks-report/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →