[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fV0E-w_MfcOxNhnZYfBtjshiIQT7q7IZdwvCZrbRBsK0":3},{"article":4,"iocs":43},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":26,"category":27,"article_tags":30},"2d722875-cae9-4aa5-9c0a-a4e7eb8f7f72","CISA Vulnerability Review","cisa-vulnerability-review-90a843","Most compromises do not rely on advanced techniques or cutting-edge tools. Cyber threat actors scan the internet looking for exposed, well-known software vulnerabilities to exploit. Basic security failures enable most compromises and organizations can reduce their risk by addressing these underlying weaknesses and prioritizing vulnerabilities for action based on the risk they pose. The CISA Vulnerability Review provides organizations with critical insights into the root causes of insecure software and practical steps they can take to address these flaws to prevent exploitation. Analyzing CISA and open source data from fiscal years 2024 and 2025, the review establishes a baseline of today’s vulnerability landscape before AI-enabled vulnerability discovery becomes more widespread. The review demonstrates the importance of Secure by Design principles in shifting cybersecurity efforts from reacting to threat actors to proactively fixing preventable software flaws. The review also identifies common software weaknesses that contribute to exploitable vulnerabilities and details practices software producers can use to prevent these weaknesses from recurring. By examining the patterns across vulnerability data, the review helps organizations focus on systemic improvements that can reduce entire classes of vulnerabilities rather than addressing individual vulnerabilities only after they are discovered. Additionally, the review shows organizations how to prioritize vulnerabilities for action using the framework outlined in Binding Operational Directive 26-04: Prioritizing Security Based on Risk. This framework evaluates vulnerabilities using four key criteria: exposure status, Known Exploited Vulnerability (KEV) Catalog status, potential for automated exploitation, and technical impact.","A new CISA Vulnerability Review for fiscal years 2024-2025 reveals that most cyber compromises exploit well-known software vulnerabilities due to basic security failures. The review emphasizes adopting Secure by Design principles and provides practical steps for organizations to proactively address software flaws and common weaknesses. It also introduces a risk-based framework for prioritizing vulnerability remediation based on exposure, KEV status, exploitability, and technical impact.","CISA review highlights common vulnerabilities and offers risk-based prioritization for organizations.","PUBLICATION CISA Vulnerability Review Fiscal Years 2024 and 2025 Publish DateAugust 26, 2026 CISA Vulnerability Review Fiscal Years 2024 and 2025 Related topics: Cybersecurity Best Practices , Critical Infrastructure Security and Resilience , Risk Management Most compromises do not rely on advanced techniques or cutting-edge tools. Cyber threat actors scan the internet looking for exposed, well-known software vulnerabilities to exploit. Basic security failures enable most compromises and organizations can reduce their risk by addressing these underlying weaknesses and prioritizing vulnerabilities for action based on the risk they pose. The CISA Vulnerability Review provides organizations with critical insights into the root causes of insecure software and practical steps they can take to address these flaws to prevent exploitation. Analyzing CISA and open source data from fiscal years 2024 and 2025, the review establishes a baseline of today’s vulnerability landscape before AI-enabled vulnerability discovery becomes more widespread. The review demonstrates the importance of Secure by Design principles in shifting cybersecurity efforts from reacting to threat actors to proactively fixing preventable software flaws. The review also identifies common software weaknesses that contribute to exploitable vulnerabilities and details practices software producers can use to prevent these weaknesses from recurring. By examining the patterns across vulnerability data, the review helps organizations focus on systemic improvements that can reduce entire classes of vulnerabilities rather than addressing individual vulnerabilities only after they are discovered. Additionally, the review shows organizations how to prioritize vulnerabilities for action using the framework outlined in Binding Operational Directive 26-04: Prioritizing Security Based on Risk. This framework evaluates vulnerabilities using four key criteria: exposure status, Known Exploited Vulnerability (KEV) Catalog status, potential for automated exploitation, and technical impact. Resource Materials Resource Name File Type File Size Language CISA Vulnerability Review Fiscal Years 2024 and 2025 PDF, 3.26 MB 3.26 MB English Tags Audience: Executives, Federal Government, Industry, Small and Medium Businesses, State, Local, Tribal, and Territorial Government Language: English Topics: Critical Infrastructure Security and Resilience, Cyber Threats and Response, Cybersecurity Best Practices, Information and Communications Technology Supply Chain Security, Malware, Phishing, and Ransomware, Risk Management Related Resources Feb 04, 2025 External, Publication Guidance and Strategies to Protect Network Edge Devices Dec 18, 2024 Publication Mobile Communications Best Practice Guidance Jun 25, 2020 Publication CISA Regional Offices Jul 29, 2026 Publication 2026 Minimum Elements for a Software Bill of Materials (SBOM)","https:\u002F\u002Fwww.cisa.gov\u002Fresources-tools\u002Fresources\u002Fcisa-vulnerability-review",null,"2026-08-26T12:00:00+00:00","2026-08-26T16:00:36.44356+00:00",8,[18,21,24],{"name":19,"type":20},"CISA","vendor",{"name":22,"type":23},"AI-enabled vulnerability discovery","technology",{"name":25,"type":23},"Secure by Design","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":26,"icon":13,"name":28,"slug":29},"Vulnerabilities","vulnerabilities",[31,33,38],{"category":32},{"id":26,"icon":13,"name":28,"slug":29},{"category":34},{"id":35,"icon":13,"name":36,"slug":37},"c5c77cdb-f7d7-4990-9436-c81dcbff1163","Policy","policy",{"category":39},{"id":40,"icon":13,"name":41,"slug":42},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[]]