{
  "id": 9420478,
  "title": "The Same Flaws Keep Getting Exploited: Reading CISA's Secure-by-Design Review as an Operations Problem",
  "url": "https://urgent.news/2026/09/23/the-same-flaws-keep-getting-exploited-reading-cisas-secure-by-design",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-23T21:20:11.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/stark_zhuang_df5076f35c68/the-same-flaws-keep-getting-exploited-reading-cisas-secure-by-design-review-as-an-operations-6je"
  },
  "original_language": "en",
  "account": "CISA's review of exploited vulnerabilities in 2024 and 2025 reveals a troubling pattern: many of the flaws targeted by attackers were not novel discoveries, but rather previously identified and fixed defects on systems that had not applied the patches. This observation underscores the importance of not merely detecting vulnerabilities, but ensuring they are properly applied and maintained. The review identifies three recurring characteristics among the exploited vulnerabilities: internet-facing components that do not require user interaction to be reached, flaws disclosed prior to exploitation, and devices difficult to update, including edge appliances, embedded devices, and end-of-support software. The root cause of the persistent issue lies in the system architecture, not patch management. Devices that cannot be rebooted during business hours or have reached end-of-support status pose ongoing risks regardless of the availability of patches. The review highlights structural issues hindering effective patch application. Inventory gaps, where organizations are unaware of owned devices, maintenance windows that prevent timely updates, end-of-support hardware lacking vendor support, and ownership ambiguity among multiple teams all contribute to unpatched vulnerabilities. While CISA does not claim defenders ignored advisories, the review suggests that common failure modes stem from these structural issues. To address the problem, CISA recommends a shift in vulnerability management priorities. Instead of solely scoring findings by CVSS, organizations should prioritize known, patchable, and reachable flaws by building a comprehensive reachability inventory of internet-facing systems, including appliances, and tracking end-of-support dates as a risk input. Proactively authorizing maintenance for edge devices and assigning ownership per device class can also help. These steps, while not requiring new tools, necessitate a decision to treat internet-facing appliances with exploited vulnerabilities as a distinct problem from internal servers with similar scores. Ultimately, CISA's retrospective review demonstrates that the exploited population is dominated by known, patchable, and reachable flaws. Solving this issue requires proactive measures such as inventory management, end-of-support tracking, and establishing maintenance pathways that do not rely on infrequent windows of opportunity.",
  "summary": "The Same Flaws Keep Getting Exploited: Reading CISA's Secure-by-Design Review as an Operations Problem CISA reviewed the vulnerabilities exploited during 2024 and 2025 and reported a pattern that should be uncomfortable for anyone running a patch program: most of the exploited flaws were not new discoveries. They were defects that had been identified years earlier, and in many cases fixed, on…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}