A July 2026 report by Orca Security, analyzing data from over 1200 organizations in Q2 2026, revealed that 99.9% of AI package vulnerabilities with available patches remain unaddressed. The study found that 81% of organizations using AI packages had at least one known vulnerability, with an average CVSS score of 8.79, indicating high criticality. This situation is attributed to the fear of breaking AI agent functionality with updates, unclear responsibility for patching transitive dependencies, and a cultural focus on AI creativity over essential security maintenance. AI
IMPACT Highlights a critical gap in AI security practices, where unpatched vulnerabilities pose significant risks despite available fixes, potentially impacting enterprise adoption and trust.
RANK_REASON The cluster reports on findings from a security research report about AI package vulnerabilities. [lever_c_demoted from research: ic=1 ai=1.0]
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →