AI‑Related CVE Volume Surges 49% YoY, Patch Lag Leaves 46% of KEVs Unpatched Since 2025
What Happened — Cisco Talos reports a 49 % year‑over‑year increase in AI‑related CVEs, with the total daily count approaching 200 by June 2026. Despite the rise, 46 % of actively‑exploited (KEV) vulnerabilities still stem from 2025 or earlier, highlighting a widening gap between discovery and remediation.
Why It Matters for Compliance & Audit Readiness
- Continuous‑compliance programs must map patch‑management controls to SOC 2 CC6.1 (System Operations) and demonstrate timely remediation evidence.
- Evidence of systematic vulnerability prioritisation (e.g., EPSS‑driven patching) satisfies the “risk mitigation” requirement of SOC 2 CC6.2.
- A documented, auditable patch‑lifecycle closes the control gap that Talos flags, providing defensible audit artifacts.
Who Is Affected — Enterprises with networking gear, AI‑enabled services, and SaaS platforms; broadly the TECH_SAAS sector.
Recommended Actions
- Align your vulnerability‑management process with EPSS scoring to prioritise high‑probability exploits.
- Integrate automated patch‑status collection into your continuous‑monitoring pipeline to produce SOC 2‑ready evidence.
- Review and update your control‑mapping repository to reflect the growing AI‑related CVE surface. Source: https://blog.talosintelligence.com/dont-swing-at-everything/
Technical Notes — The trend covers ~452 AI‑related CVEs in 2026, with networking‑gear KEVs now 24 % of the KEV pool. A 30‑90 day enterprise patch window is being exceeded; 46 % of KEVs trace back to 2025 or earlier. Source: https://blog.talosintelligence.com/dont-swing-at-everything/