VORANT. Threat Intelligence Sign in Get the full feed

NCSC proposes forgivable vs unforgivable bug model

low vulnerability

NCSC UK publishes a research framework to classify software vulnerabilities as 'forgivable' or 'unforgivable' based on how easy mitigations are to implement.

This NCSC UK research paper builds on Steve Christie's 2007 MITRE concept of 'unforgivable vulnerabilities' to propose a structured methodology for classifying software flaws. Using the CWE Top 25 Most Dangerous Software Weaknesses (2023) as source data, the NCSC identifies 11 top-level mitigations and scores each on cost, knowledge, and technical feasibility to derive an 'ease of implementation' rating (easy, medium, hard). Vulnerabilities whose root-cause mitigations are rated 'easy' are deemed 'unforgivable' — meaning they represent a disregard for basic secure development practice — while those requiring complex, costly, or poorly understood mitigations are considered 'forgivable'.

The paper is a policy/methodology document rather than a threat report: it contains no IOCs, active campaigns, or named threat actors, and references known past vulnerabilities (e.g., MOVEit CVE-2023-34362/36934, FortiGate CVE-2023-27997) only as illustrative examples of prior exploitation, not as new findings. Its stated goal is to encourage vendors and developers to eradicate entire vulnerability classes by hardening operating systems, development frameworks, and secure coding practices, and to prioritize mitigations like input validation, output encoding, sandboxing, and adoption of memory-safe languages such as Rust.

From an intelligence perspective, this is a low-urgency, forward-looking research and awareness publication aimed at software vendors and security engineering teams rather than defenders responding to active threats. It has no bearing on current attack surface or incident response priorities, but may inform longer-term secure development lifecycle (SDLC) policy and vendor engagement strategies.

Mentioned in this report

Vulnerabilities CVE-2023-27997KEVCVE-2023-34362KEVCVE-2023-36934templated

Source reporting: https://www.ncsc.gov.uk/report/a-method-to-assess-forgivable-vs-unforgivable-vulnerabilities

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free