The newly published CISA Vulnerability Review for fiscal years 2024 and 2025 delivers a blunt message: the breaches making headlines rarely rely on zero-days. Instead, the agency found that most damage came from simple, well-documented software weaknesses and known exploited vulnerabilities that organizations still leave exposed to the internet. As the report puts it, “most compromises have not relied on advanced techniques.”
According to the review, published in August 2026 by the Cybersecurity and Infrastructure Security Agency, opportunistic criminals scanning for exposed assets – not coordinated nation-state crews – drove the bulk of activity. “In fiscal years 2024 and 2025, most cyber threat activity was not coordinated threat actor groups leveraging zero-day exploits. Instead, it was opportunistic criminals scanning the internet for exposed vulnerabilities created by insecure software.” The agency frames the entire document as a baseline snapshot of the vulnerability landscape before AI-enabled discovery becomes widespread.
Known Exploited Vulnerabilities Follow a Predictable Playbook
One of the sharpest insights in the CISA Vulnerability Review concerns the KEV Catalog, the agency’s list of high-risk CVEs with confirmed active exploitation. Rather than spreading evenly across the threat landscape, these flaws cluster tightly. The report notes that known exploited vulnerabilities “cluster tightly around a smaller group of high-impact, reliably exploitable vulnerability types that offer consistent, scalable attack paths.”
Memory safety, injection, and improper input validation dominated. In FY2024 those three categories accounted for 19.8%, 10.1%, and 8.1% of the KEV Catalog respectively. Most telling of all, “41.5% of KEVs map to stubborn weaknesses” – flaws MITRE has tracked in its CWE Top 25 year after year. Some issues MITRE labeled “unforgivable” back in 2007 are still being exploited in 2025.
Injection, Cross-Site Scripting, and Aging Infrastructure
Across the full CVE dataset, injection-related weaknesses represented 10.1% of all CVEs in FY2024 and 9.2% in FY2025. Cross-site scripting (CWE-79) topped the charts both years, underscoring how poor input validation keeps enabling session hijacking and credential theft. The report distills the threat actor strategy simply: they “use simple, reliable techniques that work across multiple products and environments.”
Exposed network services compound the problem. CISA found that 26% of critical infrastructure entities scanned exposed vulnerable network services, with roughly 18% still running FTP servers. Meanwhile, 51% of scanned entities ran unsupported software linked to over half of KEVs, and 91% relied on deprecated SSL/TLS protocols left unsecured for a median of 459 days. These aging systems become, in the report’s words, “easy entry points for intrusions.”
A Shift From CVSS to Real-World Risk
The CISA Vulnerability Review documents a major change in how the agency prioritizes fixes. CVSS scores, it argues, “reflect theoretical severity, not real-world impact” and can mislead teams. Prioritization now hinges on four variables: asset exposure, KEV status, exploit automation, and technical impact. Aligned with Binding Operational Directive 26-04, this approach pushes organizations toward the Stakeholder-Specific Vulnerability Categorization framework for smarter triage.
Real-world case studies drive the point home. The report details how the Chinese state-sponsored group Salt Typhoon exploited widely known, unpatched CVEs since at least 2021 to infiltrate telecommunications, transportation, and military infrastructure worldwide. The lesson is stark: “If you’re not patching KEVs, you’re not protected.”
Secure by Design Is the Way Out
Ultimately, the review calls for a cultural shift. “Organizations must shift from reacting to threat actors to fixing the fundamental flaws those actors exploit.” CISA urges software producers to build products that are secure at inception, adopt memory-safe languages such as Rust or Swift, publish memory-safe roadmaps, and embrace software bills of materials. End-user organizations are pointed toward the Cybersecurity Performance Goals 2.0 and no-cost services like Cyber Hygiene Vulnerability Scanning, which the agency says delivers a 40% reduction in exposed external vulnerabilities within the first year.
The full report, packed with figures on stubborn weaknesses and KEV remediation timelines, is available directly from the agency in the complete CISA Vulnerability Review PDF. Its core takeaway is one defenders have heard before but too often ignore: the fundamentals still win. Patch the known exploited vulnerabilities, retire end-of-support software, validate every input, and demand secure-by-design products from vendors. The threat actors, after all, are counting on you not to.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!