HomeIntelligenceBrief
BREACH BRIEF🟡 Medium ThreatIntel

AI‑Related CVE Volume Surges 49% YoY, Patch Lag Leaves 46% of KEVs Unpatched Since 2025

Cisco Talos notes a 49 % YoY rise in AI‑related CVEs and that nearly half of actively‑exploited KEVs are still from 2025 or earlier, exposing a critical patch‑management gap that compliance programs must address.

LiveThreat™ Intelligence · 📅 July 24, 2026· 📰 blog.talosintelligence.com
🟡
Severity
Medium
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
2 recommended
📰
Source
blog.talosintelligence.com

AI‑Related CVE Volume Surges 49% YoY, Patch Lag Leaves 46% of KEVs Unpatched Since 2025

What Happened — Cisco Talos reports a 49 % year‑over‑year increase in AI‑related CVEs, with the total daily count approaching 200 by June 2026. Despite the rise, 46 % of actively‑exploited (KEV) vulnerabilities still stem from 2025 or earlier, highlighting a widening gap between discovery and remediation.

Why It Matters for Compliance & Audit Readiness

  • Continuous‑compliance programs must map patch‑management controls to SOC 2 CC6.1 (System Operations) and demonstrate timely remediation evidence.
  • Evidence of systematic vulnerability prioritisation (e.g., EPSS‑driven patching) satisfies the “risk mitigation” requirement of SOC 2 CC6.2.
  • A documented, auditable patch‑lifecycle closes the control gap that Talos flags, providing defensible audit artifacts.

Who Is Affected — Enterprises with networking gear, AI‑enabled services, and SaaS platforms; broadly the TECH_SAAS sector.

Recommended Actions

  • Align your vulnerability‑management process with EPSS scoring to prioritise high‑probability exploits.
  • Integrate automated patch‑status collection into your continuous‑monitoring pipeline to produce SOC 2‑ready evidence.
  • Review and update your control‑mapping repository to reflect the growing AI‑related CVE surface. Source: https://blog.talosintelligence.com/dont-swing-at-everything/

Technical Notes — The trend covers ~452 AI‑related CVEs in 2026, with networking‑gear KEVs now 24 % of the KEV pool. A 30‑90 day enterprise patch window is being exceeded; 46 % of KEVs trace back to 2025 or earlier. Source: https://blog.talosintelligence.com/dont-swing-at-everything/

📰 Original Source
https://blog.talosintelligence.com/dont-swing-at-everything/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →