High-profile attacks are often ascribed to unknown vulnerabilities and sophisticated tooling. Yet a fresh review from the US Cybersecurity and Infrastructure Security Agency (CISA) paints a decidedly more mundane picture. Throughout 2024 and 2025, most compromises leaned on simple, long-familiar weaknesses in internet-facing systems rather than on zero-day flaws.
The Same Weaknesses, Again and Again
CISA cross-referenced CVE data, the Known Exploited Vulnerabilities (KEV) catalog, and the findings of hands-on organizational assessments. Notably, the pattern recurred across every source. Time and again, adversaries exploited input-validation errors, memory-safety issues, injections, and access-control deficiencies. Consequently, such weaknesses furnish predictable and scalable avenues of intrusion.
What the KEV Catalog Reveals
The KEV catalog proves especially telling. Over the two-year span, 41.5% of its entries stemmed from so-called persistent weaknesses that MITRE has documented for years. Indeed, some of these flaws were deemed unacceptably trivial as far back as 2007, yet they continued to surface in products well into 2025. Rather than blaming the sophistication of attacks, CISA attributes this recurrence to systemic development shortcomings.
Fragile External Infrastructure Compounds the Risk
The condition of external infrastructure only sharpens the problem. Among the critical-infrastructure assets examined, 26% left vulnerable network services exposed. Furthermore, 51% ran unsupported software, while a striking 91% relied on outdated SSL/TLS versions.
For these legacy protocols, the median interval during which an issue lingered unremediated reached 459 days. As a result, convenient entry points remained wide open to attackers for well over a year.
Rethinking Prioritization Beyond CVSS
Against a backdrop of mounting vulnerability counts, CISA urges organizations to lean less exclusively on the CVSS score. Instead, the agency recommends weighing four factors together.
- Internet exposure: Whether the affected system is reachable from the internet.
- KEV inclusion: Whether the vulnerability appears in the KEV catalog.
- Exploitation automation: Whether an exploit can be readily automated.
- Attacker control: What degree of control an adversary gains after a successful breach.
Ultimately, this approach should surface the truly dangerous problems far more quickly.
CISA’s Recommendations for Reducing Risk
To curb exposure, CISA advises tackling internet-facing KEV vulnerabilities first and inspecting systems for signs of compromise. Beyond that, organizations should disable unnecessary insecure services, enforce encryption and robust authentication, and update software regularly. Meanwhile, developers ought to eliminate recurring classes of errors at the design stage, before they ever ship.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.