CISA Publishes FY24-25 Vulnerability Landscape Review
CISA's Vulnerability Review analyzes FY2024-2025 data to highlight root-cause software weaknesses and a risk-based prioritization framework under BOD 26-04.
CISA released a Vulnerability Review report analyzing agency and open-source vulnerability data from fiscal years 2024 and 2025 to establish a baseline understanding of the current vulnerability landscape, particularly ahead of anticipated shifts driven by AI-enabled vulnerability discovery. The report emphasizes that most successful compromises stem not from sophisticated tradecraft but from opportunistic exploitation of well-known, unpatched vulnerabilities exposed to the internet, underscoring persistent gaps in basic security hygiene across organizations.
The review promotes Secure by Design principles, urging software producers to address recurring classes of software weaknesses at the root rather than patching individual vulnerabilities reactively. It identifies common weakness patterns contributing to exploitable flaws and provides guidance for eliminating entire vulnerability classes through improved development practices. This systemic approach is intended to reduce the overall attack surface available to opportunistic threat actors who rely on internet-wide scanning to find exposed, exploitable systems.
Additionally, the report operationalizes the prioritization framework from Binding Operational Directive 26-04, which evaluates vulnerabilities using four criteria: internet exposure status, presence in CISA's Known Exploited Vulnerabilities (KEV) Catalog, potential for automated/mass exploitation, and technical impact. This framework is intended to help defenders triage remediation efforts based on real-world risk rather than treating all vulnerabilities as equally urgent. The document is informational/policy guidance rather than an alert on a specific active threat.
Source reporting: https://www.cisa.gov/resources-tools/resources/cisa-vulnerability-review
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free