CISA: Most exploited vulnerabilities should have been eradicated decades ago
Organizational culture and systemic gaps in Secure by Design adoption blamed for sorry state of affairs
The Cybersecurity and Infrastructure Security Agency (CISA) has highlighted that many of the most exploited vulnerabilities should have been eliminated decades ago. Examining vulnerabilities from 2024 and 2025, CISA found that the majority of those receiving Common Vulnerabilities and Exposures (CVEs) and appearing in the Known Exploited Vulnerability (KEV) catalog are decades-old flaws that should have been addressed.
Injection-related weaknesses like cross-site scripting (XSS), OS command injections, and SQL injections were among the most common across both CVEs and KEV records. Improper input validation, a single most-common weakness type on both lists, was identified as a significant issue. CISA emphasizes that resolving these fundamental issues would eliminate a substantial portion of today's most common compromises.
The persistence of these vulnerabilities, despite being labeled "stubborn" or "unforgivable" in previous reports, illustrates a problem rooted in organizational culture, developer workflows, and systemic gaps in Secure by Design (SBD) adoption. CISA urges software vendors to adopt SBD practices and highlights the need for stronger cybersecurity measures, including prioritizing vulnerabilities, collaboration across industry and government, and leadership attention to cyber risk as a business risk and national security threat.
Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.