Ethical Hacking News
CISA warns that most exploited vulnerabilities should have been eradicated decades ago, but instead, they continue to plague modern software, emphasizing the need for Secure by Design practices to address these persistent security issues.
Most exploited vulnerabilities are decades-old and should have been eradicated by now. The majority of exploited vulnerabilities are related to injection attacks (XSS, OS command injections, SQL injections) and poor input validation. The persistence of vulnerabilities is attributed to organizational culture and systemic gaps in Secure by Design adoption. CISA emphasizes the need for proactive security measures, such as adopting SBD practices and prioritizing vulnerability remediation. The importance of software buyers choosing vendors that meet certain security standards and ensuring the presence of SBOMs to mitigate supply chain risk.
Cybersecurity experts and government agencies have long warned about the dangers of software vulnerabilities, but recent data from the Cybersecurity and Infrastructure Security Agency (CISA) paints a stark picture of the persistent nature of these issues. According to CISA's latest review, most exploited vulnerabilities should have been eradicated decades ago, but instead, they continue to plague modern software, causing significant security breaches and compromising sensitive data.
The review, which examined software vulnerabilities across 2024 and 2025, found that the majority of the most exploited vulnerabilities belonged to decades-old flaws that should have been addressed by now. Injection-related vulnerabilities, such as cross-site scripting (XSS), OS command injections, and SQL injections, were among the most common, along with bugs introduced by vendors that didn't properly mitigate against improper input validation.
CISA attributes the persistence of these vulnerabilities to organizational culture and systemic gaps in Secure by Design (SBD) adoption. The agency argues that the problem is not technical complexity but rather the failure of organizations to prioritize vulnerability remediation and adopt SBD practices. By doing so, CISA emphasizes that software can be designed to be secure from the outset, eliminating the need for reactive patching and reducing the likelihood of exploitation.
The findings are particularly concerning, as they highlight the continued reliance on outdated and easily exploitable vulnerabilities. CISA notes that seven of the top 10 CWEs (Common Weakness Enumeration) seen on the CVE (Common Vulnerabilities and Exposures) list belong to MITRE's "stubborn weaknesses," which were first identified in a 2007 report. These weaknesses have persisted for nearly two decades, demonstrating the need for a fundamental shift in how organizations approach software development and security.
The review also highlights the importance of software buyers choosing vendors that meet certain security standards, such as those outlined by CISA. Ensuring the presence of software bills of materials (SBOMs) to track supply chain risk is also crucial in mitigating the impact of these vulnerabilities.
To address this pervasive issue, CISA is once again recommending that organizations adopt SBD practices, prioritizing vulnerability remediation and improving the automation of configurations, monitoring, and updates. By doing so, CISA argues that stronger cybersecurity can be achieved, and organizations can shift from reacting to threat actors to proactively fixing the fundamental flaws that those actors exploit.
The persistence of these vulnerabilities serves as a stark reminder of the ongoing need for robust cybersecurity measures and the importance of adopting Secure by Design practices. By prioritizing security and taking proactive steps to address these vulnerabilities, organizations can significantly reduce the risk of security breaches and protect sensitive data.
Related Information:
https://www.ethicalhackingnews.com/articles/CISA-Persistent-Vulnerabilities-Plague-Modern-Software-Urging-Adoption-of-Secure-by-Design-Practices-ehn.shtml
https://www.theregister.com/security/2026/08/28/cisa-most-exploited-vulnerabilities-should-have-been-eradicated-decades-ago/5293194
Published: Sat Aug 29 08:28:53 2026 by llama3.2 3B Q4_K_M