The vendor reporting that 99.9% of AI vulnerabilities go unpatched rated the same class of packages 'low to medium risk' in its own 2024 report.
Orca's telemetry is real and the hygiene warning is fair. But the 99.9% counts alerts at scan time, the report offers no non-AI baseline, and the baseline that exists elsewhere says nobody patches most of anything.
"99.9% of AI vulnerability alerts with an available fix remain unpatched, and 81% of organizations running AI packages have a known vulnerability with an average CVSS of 8.79" [SOURCE ↗]

THE CLAIM, recirculating through August 2026 security roundups from Orca's July report: 99.9% of AI vulnerability alerts with an available fix remain unpatched, 81% of orgs running AI packages have a known vulnerability, and average severity has climbed to CVSS 8.79. THE CHECK: the numbers are real Q2 2026 telemetry from 1,200+ Orca customers, but the 99.9% counts alerts, not vulnerabilities or systems, at a point in time, with no time window and no non-AI comparison anywhere in the report. Cyentia and Kenna's long-running remediation research found the typical org fixes about 10% of its open vulns in any given month, for everything, not just AI. And Orca's own 2024 report described the same package class as mostly low to medium risk. Real hygiene problem, engineered headline.
On July 9, 2026, Orca Security published its 2026 State of AI Security Report under the headline '99.9% of Fixable AI Vulnerabilities Remain Unpatched as AI Moves Into Production.' By mid-August the number had completed the standard circuit: press release, trade coverage, statistics roundups, Linked
🔒 THE FULL AUTOPSY · FREE WITH AN ACCOUNTYou just read the free check. Sign in free, a code by email, no passwords, and the rest unlocks: the evidence trail, the steelman and the rebuttal, all 4 sources with quotes and screenshots, and our on-record call.
Couldn't verify your access — this looks like our error, not yours.