# Cloud Security Alliance: 81% of Organizations Run AI with Known Vulnerabilities

> The Cloud Security Alliance's 2026 state-of-AI-security report lands on an uncomfortable finding: 81 percent of organizations running AI packages have at least one known vulnerability in the stack, with an average severity score near 8.8, which is squarely in the critical range. Worse, the report says the overwhelming majority of fixable alerts are simply never patched. A few other numbers stand out. Half of the vulnerabilities catalogued now have public exploits available, a huge jump from a couple of years ago, which means these are not theoretical weaknesses. And AI-generated code fares poorly on its own security review, passing clean only a little more than half the time, with a large share tripping common OWASP flaws. The through-line is a gap between how fast AI is going into production and how slowly security is following it. Teams are shipping models and agents into live environments while the basic hygiene of patching and code review lags behind. That mismatch is exactly the kind of soft target attackers look for, and this report is a fairly blunt warning that the window is already open.

_Section: [Daily AI Updates](https://www.wortins.com/daily-ai) · Source: Cloud Security Alliance · Published Thursday, August 27, 2026_

## Wortins' read

The Cloud Security Alliance's 2026 state-of-AI-security report lands on an uncomfortable finding: 81 percent of organizations running AI packages have at least one known vulnerability in the stack, with an average severity score near 8.8, which is squarely in the critical range. Worse, the report says the overwhelming majority of fixable alerts are simply never patched. A few other numbers stand out. Half of the vulnerabilities catalogued now have public exploits available, a huge jump from a couple of years ago, which means these are not theoretical weaknesses. And AI-generated code fares poorly on its own security review, passing clean only a little more than half the time, with a large share tripping common OWASP flaws. The through-line is a gap between how fast AI is going into production and how slowly security is following it. Teams are shipping models and agents into live environments while the basic hygiene of patching and code review lags behind. That mismatch is exactly the kind of soft target attackers look for, and this report is a fairly blunt warning that the window is already open.

## Source

[Read the full story at Cloud Security Alliance](https://cloudsecurityalliance.org/blog/2026/08/18/2026-state-of-ai-security-ai-is-in-production-security-isn-t)

## Related coverage

- [Emerald AI Raises $150 Million Series A at $1.05 Billion Valuation](https://www.wortins.com/story/emerald-ai-raises-150-million-series-a-at-1-05-billion-valua-2071899e) — [Business Wire](https://www.businesswire.com/news/home/20260825127649/en/Emerald-AI-Raises-$150-Million-Series-A-at-$1.05-Billion-Valuation-to-Scale-Power-Flexible-AI-Data-Centers)
- [ShepHertz Launches AgentAnywhere, Sovereign Agentic AI Platform for Regulated Industries](https://www.wortins.com/story/shephertz-launches-agentanywhere-sovereign-agentic-ai-platfo-a80b8050) — [ShepHertz](https://aiagentstore.ai/ai-agent-news/this-week)
- [Apple Updates, AI Computers, and OpenAI's Jalapeño Chip](https://www.wortins.com/story/apple-updates-ai-computers-and-openai-s-jalape-o-chip-adb3115c) — [Stratechery](https://stratechery.com/2026/apple-updates-mini-and-studio-ai-computers-openai-jalapeno/)
- [Google DeepMind Releases Gemini Robotics 2 With Whole-Body Control](https://www.wortins.com/story/google-deepmind-releases-gemini-robotics-2-with-whole-body-c-578b43eb) — [Google DeepMind](https://deepmind.google/blog/gemini-robotics-2-brings-whole-body-intelligence-to-robots/)
- [Anthropic Signs $45 Billion Compute Deal with British Infrastructure Firm Nscale](https://www.wortins.com/story/anthropic-signs-45-billion-compute-deal-with-british-infrast-9d89144c) — [TechCrunch](https://techcrunch.com/2026/08/26/anthropic-continues-compute-gobbling-streak-in-45-billion-deal-with-nscale/)
- [AI Consciousness Debate Is a Trap, Says MIT Technology Review](https://www.wortins.com/story/ai-consciousness-debate-is-a-trap-says-mit-technology-review-54e8082c) — [MIT Technology Review](https://www.technologyreview.com/2026/08/20/1142571/ai-consciousness-debate-trap/)

---

_Curated and written by [Wortins](https://www.wortins.com) — The daily AI briefing. Every story links to its original source; the "Wortins read" on each is our own original analysis. [About Wortins & our editorial approach](https://www.wortins.com/about)._
