CISA Finds Most 2024-25 Exploits Targeted Old, Already-Patched Vulnerabilities
A CISA review of vulnerabilities exploited in 2024 and 2025 found that the majority were not newly discovered flaws but rather known defects disclosed years earlier, often with patches already available. The exploited vulnerabilities shared three common traits: they affected internet-facing components, were publicly disclosed well before exploitation occurred, and persisted on systems that are difficult to update, such as edge appliances and end-of-support hardware. CISA identified structural failures — including incomplete asset inventories, inflexible maintenance windows, and unclear device ownership — as the primary reasons patches went unapplied rather than simple negligence. The agency recommends that defenders treat actively exploited vulnerabilities as a distinct risk category, separate from general CVSS-scored findings, and build dedicated tracking for internet-facing and end-of-support systems. CISA's findings suggest that closing these gaps requires not new security tools but clearer operational ownership and architectural changes to how edge devices are managed.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in