# Unpatched Institutional Vulnerability
**Entity class:** Institutional-security concept
## Definition
An **unpatched institutional vulnerability** is a known weakness in doctrine, coordination, training, procedure, infrastructure, authority, or information flow that remains exploitable because mitigation has not been designed, deployed, enforced, or maintained across the relevant system.
## Relevance to this collection
It links cyber patching logic to [[wiki/Intelligence Failure|Intelligence Failure]], [[wiki/Failure of Imagination|Failure of Imagination]], [[wiki/Attack Surface|Attack Surface]], and [[wiki/Predictive Defense|Predictive Defense]].
## Relationships
- **master collection:** [[collections/Terrorism, Counterterrorism, and the Intelligence Environment|Terrorism, Counterterrorism, and the Intelligence Environment]].
- **convergence:** [[wiki/Counterterrorism-Cybersecurity Convergence|Counterterrorism–Cybersecurity Convergence]].
## Sources / Provenance
- [National Commission on Terrorist Attacks Upon the United States, *The 9/11 Commission Report*, July 22, 2004](https://www.9-11commission.gov/report/911Report_Ch3.htm).
**As of:** 2026-09-23