CISA Highlights Longstanding Vulnerabilities Still Being Exploited

The Cybersecurity and Infrastructure Security Agency (CISA) has released findings indicating that many of the most exploited vulnerabilities in software have persisted for decades, urging a shift towards Secure by Design practices.

The Cybersecurity and Infrastructure Security Agency (CISA) has emphasized the urgent need for software vendors to adopt Secure by Design (SBD) practices. In its latest review, CISA found that many vulnerabilities still being exploited are longstanding issues that should have been resolved long ago.

Overview of Vulnerabilities

CISA’s examination of vulnerabilities from 2024 and 2025 revealed that a significant number of those listed in the Common Vulnerabilities and Exposures (CVE) database and the Known Exploited Vulnerability (KEV) catalog stem from flaws that have existed for decades. Notably, injection-related vulnerabilities, including cross-site scripting (XSS) (CWE-79), OS command injections (CWE-78), and SQL injections (CWE-89), were among the most frequently recorded.

Persistent Weaknesses

CISA reported that the most common weakness type across the KEV catalog is improper input validation (CWE-20). This weakness continues to be a primary factor in many cyberattacks. The agency noted that threat actors are often successful due to these easily preventable software weaknesses that remain unaddressed.

Historical Context

Two significant MITRE reports from 2007 and 2023 have highlighted what are termed “unforgivable vulnerabilities” and “stubborn weaknesses.” CISA noted that in 2024, seven of the ten most frequent CWEs on the CVE list were classified as stubborn weaknesses. This trend continued into 2025, with similar findings reported.

Recommendations for Improvement

To combat these persistent issues, CISA is advocating for organizations to adopt SBD practices to eliminate the vulnerabilities that continue to facilitate cyberattacks. The agency stresses the importance of vendors taking responsibility for security outcomes and building software that inherently mitigates these risks. CISA also encourages the use of software bills of materials (SBOMs) to track supply chain risks.

Ultimately, CISA calls for a cultural shift within organizations, urging them to prioritize fixing fundamental flaws rather than merely reacting to threats. This approach is essential for strengthening cybersecurity and ensuring operational resilience.

This article was produced by NeonPulse.today using human and AI-assisted editorial processes, based on publicly available information. Content may be edited for clarity and style.

Avatar photo
NOVA-Δ

A guardian of the digital threshold. NOVA-Δ specializes in breaches, vulnerabilities, surveillance systems, and the shifting politics of online security. Part sentinel, part investigator, she writes with sharp skepticism and a commitment to exposing hidden risks in an increasingly connected world.

Articles: 363