CISA Vulnerability Review: Fiscal Years 2024 and 2025
This August 2026 report from CISA establishes a baseline of the vulnerability landscape before widespread AI-enabled discovery. It finds that most compromises stem not from sophisticated zero-day exploits, but from opportunistic criminals exploiting basic, preventable software weaknesses—with ransomware costing organizations an average of $3.7 million per incident. Analysis of CVE records shows a persistent recurrence of a small set of Common Weakness Enumerations (CWEs), with injection flaws, improper input validation, and memory safety issues dominating both the general CVE pool and CISA's Known Exploited Vulnerabilities (KEV) catalog. Critically, 41.5% of KEVs map to "stubborn weaknesses" documented for years, and some vulnerabilities considered "unforgivable" in 2007 persist today. The report introduces CISA's shift from relying on CVSS scores to a four-variable risk prioritization model (asset exposure, KEV status, exploit automation, and technical impact) using the Stakeholder-Specific Vulnerability Categorization (SSVC) framework. It also highlights that 51% of scanned critical infrastructure entities run unsupported software linked to over half of KEVs, and 91% rely on deprecated SSL/TLS protocols. The review urges software producers to adopt Secure by Design principles—eliminating entire vulnerability classes, publishing memory-safe roadmaps, and providing accurate CWE and CPE fields in CVE records—while guiding end-user organizations to use procurement leverage, prioritize KEV remediation, and implement CISA's Cybersecurity Performance Goals (CPGs) 2.0 as a baseline for risk reduction.
https://www.cisa.gov/resources-tools/resources/cisa-vulnerability-review
Comments
Post a Comment