logo

CISA: Most exploited vulnerabilities should have been eradicated decades ago

ID: 19865c19-dae0-59ae-8b57-0a079f0e4146

STIX ID: report--19865c19-dae0-59ae-8b57-0a079f0e4146

Feed Name: The Register (Security)

Threat Score
50/100

Date Published: 2026-08-28

Date Updated: 2026-08-28

...
...

CISA's review of 2024–2025 finds that decades-old, well-known vulnerability classes—such as improper input validation (CWE-20), XSS, SQL and OS command injection, and path traversal—remain among the most exploited and frequent entries in CVE and Known Exploited Vulnerability (KEV) catalogs; the agency attributes this persistence to failures in Secure by Design adoption, organizational culture, and developer workflows and urges vendors and buyers to prioritize secure development, SBOMs, and automation of security controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.