IRS left critical flaws unpatched on 6 of 7 sampled systems, watchdog says

Image Credit: The National Archives (UK) - CC BY 3.0/Wiki Commons

A new watchdog report has found that the IRS left critical cybersecurity vulnerabilities unpatched on six of the seven information systems the Treasury Inspector General for Tax Administration sampled, well past the 30-day window federal guidance sets for fixing them. TIGTA rated the IRS’s overall cybersecurity program “not effective” for fiscal year 2026, the second straight year it has reached that conclusion. The report also found hundreds of privileged accounts operating outside the IRS’s own oversight system and encryption work pushed back to 2027, all inside a tax agency that handles more sensitive personal and financial data than almost any other part of the federal government. For taxpayers, the findings raise a basic question: whether the tax returns, Social Security numbers and bank details the IRS holds are as protected as the agency is supposed to keep them — a question that matters most for anyone who has no way of independently checking the answer.

Critical Vulnerabilities Left Unpatched on 6 of 7 Systems

TIGTA’s report, numbered 2026-200-053 and titled “The IRS’s Cybersecurity Program Was Not Effective for Fiscal Year 2026,” found that 86 percent — 6 of 7 — of the information systems it sampled had critical vulnerabilities that were not remediated within 30 days, the timeframe federal cybersecurity standards set for fixing the most severe flaws. The report is dated September 15, 2026. TIGTA is the independent watchdog that audits IRS operations, and this review is part of its annual evaluation of the agency’s compliance with the Federal Information Security Modernization Act, known as FISMA. A 6-of-7 failure rate on a federal-standard deadline signals the problem is not confined to one system or one corner of the IRS’s network; the 30-day clock exists specifically because a critical flaw left unpatched is one that has had time to be discovered and exploited. The report frames the 6-of-7 result as a sample finding rather than a count of every system the IRS operates, which is standard practice for the annual FISMA-related reviews TIGTA conducts of the agency’s information security.


Inside the kit: with TIGTA describing unpatched vulnerabilities on the systems that hold taxpayer data, the family code word and a fraud evidence and report log are the two pieces of preparation worth having in place before, not after, anyone learns whether their own information was exposed. Open The Senior Fraud Defense & First-Hour Recovery Kit.

841 Privileged Accounts Outside the IRS’s Own Safeguards

As of June 2026, the IRS had 841 privileged service accounts spread across 313 systems that were operating outside the agency’s own privileged account management system, according to the report. Privileged accounts carry elevated access — the kind that can view, change or export taxpayer data — and TIGTA also found that one privileged user had unapproved access to taxpayer data. Separately, 29 percent of the high-value asset systems TIGTA reviewed — 2 of 7 — lacked endpoint detection and response tools, the software meant to flag and stop an intrusion once it starts. TIGTA frames the findings as connected: an account with elevated access that sits outside formal oversight, on a system without modern intrusion detection, is a gap of a different order than a routine process note. A privileged service account typically runs automated processes rather than belonging to a single employee, which is part of why 841 of them spread across 313 systems is significant — each one represents a potential path into taxpayer data that the IRS’s own management system was not tracking as of the June 2026 snapshot TIGTA reviewed.

Data-at-Rest Encryption Pushed Back to Fiscal Year 2027

The IRS had targeted full implementation of data-at-rest encryption — which scrambles stored data so it is unreadable without a key, even if a system is breached — for completion years earlier, but the report found the project still incomplete as of April 2026, with procurement delays pushing the finish date to fiscal year 2027. TIGTA’s report warns that until encryption gaps and the other weaknesses are closed, taxpayer data “could be vulnerable to inappropriate and undetected use, modification, or disclosure.” Three of the six function areas TIGTA evaluated under FISMA — categories that include identity management, detection and response, and recovery planning — were rated below an acceptable maturity level. The IRS had originally targeted fiscal year 2024 for finishing the encryption project, so the fiscal 2027 completion date TIGTA reported marks a multi-year slip from that original goal, not a modest scheduling adjustment.

TIGTA’s “Not Effective” Rating and Zero Recommendations

Diana M. Tengesdal, Deputy Inspector General for Audit at TIGTA, signed the memorandum accompanying the report. Despite the not-effective rating, TIGTA made no new recommendations in this particular review, noting that earlier reports had already made recommendations covering the same weaknesses, which the IRS has not yet fully resolved. That decision does not mean TIGTA considers the problems solved; it reflects that this review measured whether the IRS had acted on findings already on record, and the not-effective rating itself is TIGTA’s formal way of stating, on the public record, that it had not. The Journal of Accountancy reported that this marks the second consecutive year TIGTA has rated the IRS’s cybersecurity program not effective, a finding the report leaves on the public record under Tengesdal’s signature.


What Happens if IRS Systems Are Already the Weak Point

TIGTA’s report found that most of the IRS systems it sampled still had critical vulnerabilities left unpatched well past the 30-day remediation window, and hundreds of privileged accounts sitting outside the agency’s own oversight — a taxpayer has no way to check which systems those are or whether their own record touched one of them. That gap leaves the question of readiness sitting with the taxpayer, not the agency.

The Senior Fraud Defense & First-Hour Recovery Kit lays out the free credit-freeze steps and the first-hour recovery plan for exactly that kind of readiness.

See the free credit-freeze steps in The Senior Fraud Defense & First-Hour Recovery Kit.

This article was produced with AI assistance and checked against the primary sources linked above.

Leave a Reply

Your email address will not be published. Required fields are marked *