Security1 distinct publisher2 min readPublished
Its review of fiscal 2024 and 2025 says opportunistic scanning of known, internet-exposed flaws drove most compromises. The fix, it argues, belongs to software producers, not to defenders patching faster.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Class elimination compounds in a way patching does not: remove the class and you remove bugs nobody has reported yet [9]. That is the strongest part of CISA's case, and its ceiling is visible in CISA's own number. Subtract the stubborn-weakness share of 41.5% from the catalog and 58.5% of KEV entries sit outside that set [5][17]. Clearing the stubborn classes is worth doing. Most of the exploited catalog still has to be handled one CVE at a time.
The age of the list is the part worth putting to a vendor. MITRE's 2007 standard for an unforgivable vulnerability covered flaws with a documented mistake, an obvious attack path and a trivial exploit [6]. Three of the ten most common CWEs today meet it, which is 30% of the current top ten [7][18]. CISA reads that persistence as a failure of organizational culture and Secure by Design adoption rather than an unsolved engineering problem [8].
The bill is where the review goes quiet. Eliminating memory-safety flaws usually means rewriting large C and C++ codebases in memory-safe languages, which the agency concedes is a multi-year and expensive undertaking [13], and its own summary of the requirement is technical discipline plus executive buy-in [12]. Help Net Security flags a gap the review leaves open: why years of voluntary Secure by Design pledges underdelivered, and why vendors resist owning security outcomes for customers, a phrase that reads as legal liability [14][10].
That leaves procurement as the only enforcement surface on offer. Secure by Demand tells buyers to make security a contract condition and to ask which vulnerability classes a vendor has already eliminated, whether the SBOM is machine-readable, whether phishing-resistant authentication ships on by default, and whether security logs are available [15]. The class question is the one with a falsifiable answer. A vendor that says injection is gone can be held to that the next time an injection CVE appears in its own advisory feed. CISA also tells developers to prioritise weaknesses that attackers exploit together, since many exploited vulnerabilities span multiple categories [11]; the buyer-side version is refusing a roadmap that closes one link in a chain and calls it done.
Set the two findings side by side. Verizon's 2026 report puts vulnerability exploitation as the most common route to initial access [3], and CISA says the vulnerabilities doing that work were known and internet-exposed [2]. Both point at the same operational question: what of yours answers from the internet, and how old is the newest unpatched CVE on it.
Ranked by verification strength, evidence, and original report placement.
CISA published the CISA Vulnerability Review: Fiscal Years 2024 and 2025 in August 2026.
The review found that most compromises in fiscal 2024 and 2025 did not involve nation-state zero-days or advanced tradecraft, but came from opportunistic criminals scanning the internet for exposed, known vulnerabilities created by insecurely written software.
Verizon's 2026 Data Breach Investigations Report, released earlier in the year, found that vulnerability exploitation is now the most common way attackers gain initial access to target networks.
CISA's analysis of CWE tags across published CVEs found a persistent cluster of avoidable coding errors driving a disproportionate share of real-world exploitation: injection flaws, improper input validation, memory-safety failures, path traversal and broken access control.
In CISA's Known Exploited Vulnerabilities catalog, 41.5% of entries map to what MITRE calls stubborn weaknesses: flaw types that have appeared on the CWE Top 25 nearly every year since 2019.
CISA cites MITRE's 2007 report on unforgivable vulnerabilities, defined as flaws stemming from a well-documented mistake, with an obvious attack path and a trivial exploit.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 1, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
43 days, 26 percent, and a pitch that saves you 29 minutes1 distinct publisher
security
CISA and the FBI put "exceptionally risky" software practices in writing, and buyers get the list1 distinct publisher
build
MLflow's webhook tester is now a credential-theft tool, and it is on CISA's KEV list1 distinct publisher
security
CISA puts TrueConf Server in the exploited bucket, and port 4307/TCP does not care about your LAN1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Faithful reading of one document, checked by no one
The specifics are unusually crisp for a policy story — 41.5% of the exploited-vulnerability catalog, three of ten common weakness types, two short verbatim quotes — and all of them come from the same August 2026 CISA review, read by one outlet. The corroborating Verizon breach report arrives without a number or a date. What is quoted is quotable; what is missing is a second pair of eyes on the underlying counts and on the claim about what the review leaves out.
The adoption signal is the shortfall itself
The only measurement of uptake here runs backwards: after years of CISA asking for Secure by Design, a two-fiscal-year review finds the same avoidable coding errors driving most intrusions, and 41.5% of exploited-flaw entries land on weakness types that have been on the Top 25 nearly every year since 2019. Nobody in this reporting counts a vendor that eliminated a class, published a roadmap, or lost a deal over an SBOM question. Secure by Demand is guidance with no observed buyer behind it yet.
The ask outruns the proof, and the piece admits it
Class elimination is presented as the fix, yet the mechanism that would deliver it — producers accepting outcome ownership because enough buyers ask the same questions — has no demonstrated instance anywhere in this reporting. What keeps the overstatement modest is that the objections arrive in the same breath: Help Net Security notes CISA has been asking for years, that memory-safe rewrites are a multi-year bill, and that the review skips why voluntary pledges failed. A story that carries its own counterargument is not selling hard.
An agency reassigning the bill, a trade press glad to hear it
Read the interests plainly. CISA is proposing that remediation cost move from its constituency, the defenders, onto software producers — and 'owning security outcomes', as the outlet spots, is liability language in engineering dress. The one outside statistic comes from Verizon, a company that sells into the market its breach report describes. Help Net Security's readers are the people who would be relieved of the patch treadmill. None of that makes the finding wrong; it does explain why the framing lands so cleanly and why a vendor rebuttal is conspicuously absent.
Traceable to a public document, unverified beyond it
We can be fairly firm about what CISA said and when it said it — the review is named, dated and quoted. We are on thinner ground about the numbers behind the quotes, about how much of the ecosystem has moved, and about whether the review truly sidesteps the pledge and liability questions. One outlet, one document, and the two claims most likely to be argued over are the ones nobody has independently tested.