CISA: Most exploited vulnerabilities should have been eradicated decades ago

https://image.theregister.com/246588.jpg?imageId=246588&x=0&y=0&cropw=100&croph=100&panox=0&panoy=0&panow=100&panoh=100&width=1200&height=683

Organizational culture and systemic gaps in Secure by Design adoption blamed for sorry state of affairs

CISA is still crying out for software vendors to adopt Secure by Design (SBD) development practices, and says in its latest review that longstanding vulnerability classes are still the most exploited.

The agency examined soft spots across 2024 and 2025, finding that the majority of those that receive CVEs and make it to the Known Exploited Vulnerability (KEV) catalog belong to decades-old flaws that should have been addressed by now.

Injection-related vulnerabilities, such as cross-site scripting (XSS) (CWE-79), OS command injections (CWE-78), and SQL injections (CWE-89) were among the most common across both CVE and KEV records in 2024-2025, CISA said.

These were joined by bugs introduced by vendors that didn’t properly mitigate against improper input validation (CWE-20) in their code – the single most-common weakness type across the KEV catalogand registered...

Copyright of this story solely belongs to theregister.com. To see the full text click HERE

Read more