logo

Verizon 2025 DBIR: Tenable Research Collaboration Shines a Spotlight on CVE Remediation Trends

ID: 6bf6ae34-77f6-573f-bde7-6cd0598eb40f

STIX ID: report--6bf6ae34-77f6-573f-bde7-6cd0598eb40f

Feed Name: Tenable Blog

Threat Score
85/100

Date Published: 2025-04-23

Date Updated: 2026-05-01

Author: Scott Caveza

...
...

Tenable Research analyzed 17 edge-device CVEs featured in the 2025 Verizon DBIR — many of them zero-days or actively exploited — and measured industry-specific remediation times, finding widespread delays in patching across vendors (Cisco, Citrix, Fortinet, Ivanti, Juniper, Palo Alto, SonicWall). The report highlights APT exploitation (ArcaneDoor/UAT4356), ransomware groups (Fog, Akira) leveraging these vulnerabilities for initial access, the inclusion of these CVEs on CISA's KEV list, and recommends rapid remediation to reduce risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.