Skip to content

Security1 publisher3 min readPublished

CISA ties 40% of 2024's exploited flaws to a handful of long-known weakness classes

The industry is still shipping the defect classes CISA has flagged for years. The case that AI coding assistants will multiply them comes from two named practitioners, not from the agency's own data.

The Watch · Security desk

Illustration accompanying CISA ties 40% of 2024's exploited flaws to a handful of long-known weakness classes

What happened

  • About 40% of the 2024 entries in the KEV catalogue came from a handful of weaknesses the agency called stubborn and described as preventable through Secure by Design practices.
  • The published CVE list more than doubled from 14,234 in FY2024 to 30,517 in FY2025, while the catalogue of exploited flaws grew only about 20% over the same period.
  • CISA found attackers mostly scanning for and exploiting known vulnerabilities and basic weaknesses that organisations had failed to patch, configure properly, or retire in time.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Miracco's argument cuts at a defender assumption still built into patch schedules: that a known flaw stays unfound while the vendor prepares a fix.
  • cost On Zahid's account the buyer pays for the producer's design decision, so a vendor shipping a preventable weakness class keeps spending less than the customer who absorbs the compromise.
  • constraint A larger pool of discovered flaws costs defenders triage capacity first, and triage is the step already failing on the small set attackers actually use.
  • contradiction The agency's data sorts defects by class, not by who or what wrote them, so the claim that AI coding tools will multiply these classes rests on practitioner reasoning about tooling speed and incentives.

Between FY2024 and FY2025 the published CVE count went from 14,234 to 30,517, an increase of 16,283 entries, or about 114% [5][1]. CISA's Known Exploited Vulnerabilities catalogue grew about 20% in the same period [6]. Discovery ran roughly 5.7 times faster than the exploited list [2]. CISA reads the gap as attackers concentrating on a relatively small set of vulnerabilities [6].

The concentration is on old defects. Memory safety and improper input validation were among the most prevalent weaknesses in both the CVE data and the KEV entries [2]. Injection flaws, including SQL injection, cross-site scripting and command injection, featured prominently, along with path traversal and missing authentication [3]. About 40% of the 2024 KEV entries came out of that handful of what CISA called "stubborn weaknesses" and well-understood design errors it describes as preventable through Secure by Design practices [4]. "Threat actors continue to succeed, in part, because simple, preventable software weaknesses remain unaddressed. Resolving fundamental issues would eliminate a significant portion of today's most common compromises," the agency wrote [7].

The entry method was equally familiar. CISA found attackers generally were not relying on exotic techniques or cutting-edge zero days, but scanning for and exploiting known vulnerabilities and basic weaknesses that organisations had failed to patch, configure properly, or retire in time [8]. Ted Miracco, CEO of Approov, said AI is making those attacks cheaper by speeding up reverse engineering, vulnerability discovery, API mapping and scraping, and the creation of exploit and automation scripts [10]. He said organisations cannot count on vulnerabilities remaining hidden from bad actors until a patch is ready [11]. "CISA's findings reinforce the need to move from treating vulnerabilities as isolated defects to addressing the underlying architectural and engineering practices that allow them to recur," Miracco said [12].

Yasir Zahid, a founding member of Secure.com, put the recurrence down to economics. "Software ships fast, security reviews happen late, and finding a flaw after release is cheaper in the short term than preventing it at design. So teams stay stuck reacting to individual findings instead of eliminating whole flaw classes at the source," he said [13]. "Right now, the cost of a vulnerability lands on the customer, not the producer," Zahid said [14]. He said input validation failures are not mainly a knowledge gap, because the systems developers work in do not enforce safe defaults or catch unsafe patterns before code merges [15].

The analysis, as ReversingLabs described it, does not measure how much of the 2024-2025 defect volume came out of AI-assisted code [3]. ReversingLabs wrote that the AI-sparked growth in vulnerability discovery has not quite translated into a corresponding expansion of the threat landscape [16]. The forward claim is conditional: that concentration of exploited flaws could become harder to manage if AI-enabled discovery expands the pool of flaws defenders must assess and prioritise [17].

What to watch

  • Whether CISA's next KEV analysis breaks out how much defect volume came from AI-assisted code.
  • Whether KEV growth stays near 20% as CVE publication volume keeps climbing.
  • Whether any procurement or liability change moves fix costs onto producers, the reordering Zahid says is missing.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories