{"id":61327,"date":"2026-08-28T11:29:00","date_gmt":"2026-08-28T11:29:00","guid":{"rendered":"https:\/\/www.theregister.com\/a\/5293194"},"modified":"2026-08-28T11:29:00","modified_gmt":"2026-08-28T11:29:00","slug":"cisa-most-exploited-vulnerabilities-should-have-been-eradicated-decades-ago","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/cisa-most-exploited-vulnerabilities-should-have-been-eradicated-decades-ago\/","title":{"rendered":"CISA: Most exploited vulnerabilities should have been eradicated decades ago"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/image.theregister.com\/246588.jpg?imageId=246588&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683\" class=\"ff-og-image-inserted\"><\/div>\n<div data-element-guid=\"d11159dd-82a3-4c53-901c-d41dec75505c\" readability=\"32.527075812274\">\n<p class=\"kicker \">security<\/p>\n<p class=\"subtitle \">Organizational culture and systemic gaps in Secure by Design adoption blamed for sorry state of affairs<\/p>\n<\/p><\/div>\n<div data-element-guid=\"4c9dc5d9-c886-4348-bf4a-01d0dc71377d\" readability=\"142.4102467508\"> <!-- placeholder(#1) --><\/p>\n<div data-element-guid=\"0fb02ed4-4174-4be5-bd5f-2eccad375723\" id=\"toplist_5293196\" class=\"column toplist desktop-floatRight mobile-floatRight layout_vertical small-12 large-3 small-abs-12 large-abs-3\">\n<div class=\"content\">\n<h3 class=\"headline t21 font-weight-bold m-font-weight-bold bg-primary color_mobile_bg-primary align-center mobile_text_align_align-center font-RobotoMono hasTextPadding mobile-hasTextPadding\"> MOST POPULAR <\/h3>\n<\/p><\/div>\n<\/div>\n<p>CISA is still crying out for software vendors to adopt Secure by Design (SBD) development practices, and says in its latest review that longstanding vulnerability classes are still the most exploited.<\/p>\n<p>The agency examined soft spots across 2024 and 2025, finding that the majority of those that receive CVEs and make it to the Known Exploited Vulnerability (KEV) catalog belong to decades-old flaws that should have been addressed by now.<\/p>\n<p>Injection-related vulnerabilities, such as cross-site scripting (XSS) (CWE-79), OS command injections (CWE-78), and SQL injections (CWE-89) were among the most common across both CVE and KEV records in 2024-2025, CISA <a href=\"https:\/\/www.cisa.gov\/resources-tools\/resources\/cisa-vulnerability-review\">said<\/a>.<\/p>\n<p>These were joined by bugs introduced by vendors that didn\u2019t properly mitigate against improper input validation (CWE-20) in their code \u2013 the single most-common weakness type across the <a href=\"https:\/\/www.theregister.com\/special-features\/2025\/02\/28\/cisas-kev-list-informs-ransomware-attacks-paper-suggests\/545145\">KEV catalog<\/a> and registered CVEs.<\/p>\n<p>\u201cThreat actors continue to succeed, in part, because simple, preventable software weaknesses remain unaddressed,\u201d CISA said in the review.&nbsp;<\/p>\n<p>\u201cResolving fundamental issues would eliminate a significant portion of today\u2019s most common compromises.\u201d<\/p>\n<p>Readers may remember two MITRE reports that have been frequently referred to and revisited since being published years ago. Findings from a 2007 edition examining what the organization called \u201c<a href=\"https:\/\/cwe.mitre.org\/documents\/unforgivable_vulns\/unforgivable.pdf\">unforgivable vulnerabilities<\/a>,\u201d and another in 2023 referring to \u201c<a href=\"https:\/\/cwe.mitre.org\/top25\/archive\/2023\/2023_stubborn_weaknesses.html\">stubborn weaknesses<\/a>,\u201d continue to crop up regularly in modern data.<\/p>\n<p>CISA said that in 2024, seven of the 10 most frequent CWEs seen on the CVE list belong to MITRE\u2019s \u201cstubborn weaknesses.\u201d&nbsp;<\/p>\n<p>Equally, seven of the 10 most frequent CWEs seen on the KEV catalog, comprising 41.5 percent of all bugs on that list, were also stubborn weaknesses. And three of the top five KEVs also stemmed from unfixed holes, a finding that CISA said demonstrates \u201chow reliably these weaknesses translate into real-world exploitation.\u201d<\/p>\n<p>For reference, these three were improper input validation (CWE-20), path traversal (CWE-22), and OS command injections (CWE-78).<\/p>\n<p>The data from 2025 follows a similar pattern, CISA said: seven of the top 10 CWES were still those considered \u201cunforgivable\u201d in 2007.<\/p>\n<p>\u201cThree of today\u2019s top 10 CWEs would have been considered \u2018unforgivable\u2019 nearly two decades ago,\u201d it said. \u201cTheir persistence today illustrates that the problem is not technical complexity: it is organizational culture, developer workflows, and systemic gaps in <a href=\"https:\/\/www.theregister.com\/on-prem\/2025\/04\/22\/cisa-officials-jump-ship-both-pushed-for-secure-by-design\/385689\">Secure by Design<\/a> adoption.\u201d<\/p>\n<p>For those who can\u2019t remember the paper published 19 years ago, unforgivable vulnerabilities are those that exist because of common, well-documented mistakes, have an \u201cobvious\u201d attack path, the exploit is simple, and attackers can locate the bug in minutes.<\/p>\n<p>The same findings can be found in CISA\u2019s Risk and Vulnerability Assessments (RVAs), the no-cost penetration tests the agency carries out on real organizations to improve their security and gain a richer understanding of the broader US cyber landscape.<\/p>\n<p>The assessments across both 2024 showed that <a href=\"https:\/\/www.theregister.com\/software\/2025\/06\/27\/cisa-nsa-repeat-call-for-memory-safe-programming-languages\/1192628\">memory safety<\/a> and improper input validation vulnerabilities are the most reliable paths to exploitation, accounting for 16.7 percent of KEV entries in 2025.<\/p>\n<div data-element-guid=\"9fdd0b54-fbe5-4571-852a-a52acde4a999\" class=\"quotebox column desktop-floatLeft mobile-floatLeft small-12 large-2 small-abs-12 large-abs-2\">\n<div class=\"content bg-octonary color_mobile_bg-octonary border-bg-quinary mobile_border-bg-quinary border-side-left mobile_border-side-left border_width_2 border_width_mobile_2 hasContentPadding mobile-hasContentPadding hasBorder mobile-hasBorder\">\n<h3 class=\"quote noLine t14 font-weight-light m-font-weight-light font-Roboto italic m-italic\"> Three of today\u2019s top 10 CWEs would have been considered \u2018unforgivable\u2019 nearly two decades ago <\/h3>\n<\/p><\/div>\n<\/div>\n<p>Injection vulnerabilities are also commonly seen in registered CVEs, although these are less commonly exploited in the real-world, especially against cyber-mature organizations.<\/p>\n<p>To tackle this pervasive issue, CISA is once again recommending organizations adopt SBD practices, eliminating the stubborn vulnerability classes that continue to support cyberattacks, decades after they were deemed too much of a lingering threat.<\/p>\n<p>It ultimately comes down to vendors helping defenders to shoulder less of the security burden. Instead of releasing patch packages that continue to <a href=\"https:\/\/www.theregister.com\/security\/2026\/07\/14\/patchpocalypse-now-microsoft-tops-last-months-record-with-622-patch-tuesday-cves\/5271434\">swell to record sizes<\/a>, just build the software responsibly in the first place.<\/p>\n<p>In CISA\u2019s view, this means \u201cowning security outcomes\u201d for customers, killing off the so-called stubborn and unforgivable weaknesses, and improving the automation of configurations, monitoring, and updates.<\/p>\n<p>Software buyers should only choose vendors that meet these requirements, and ensure they have <a href=\"https:\/\/www.theregister.com\/security\/2026\/05\/04\/ai-boms-replace-sboms-as-way-to-track-ai-agents-and-bots\/5221716\">software bills of materials (SBOMs)<\/a> in place to track <a href=\"https:\/\/www.theregister.com\/security\/2026\/04\/28\/ongoing-supply-chain-attack-targets-security-dev-tools\/5226665\">supply chain risk<\/a>.<\/p>\n<p>\u201cOrganizations must shift from reacting to threat actors to fixing the fundamental flaws those actors are known to exploit,\u201d said CISA. \u201cStronger cybersecurity begins with software that is secure by design.&nbsp;<\/p>\n<p>\u201cIt requires prioritization of vulnerabilities and collaboration across industry and government. Finally, it demands leadership attention to understand cyber risk as a business risk, a national security threat, and an impediment to operational resilience.\u201d \u00ae<\/p>\n<\/p><\/div>\n<p><img decoding=\"async\" src=\"https:\/\/image.theregister.com\/?imageId=246588&#038;width=800\">READ MORE <a href=\"https:\/\/www.theregister.com\/security\/2026\/08\/28\/cisa-most-exploited-vulnerabilities-should-have-been-eradicated-decades-ago\/5293194\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> Organizational culture and systemic gaps in Secure by Design adoption blamed for sorry state of affairs READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[63],"tags":[307],"class_list":["post-61327","post","type-post","status-publish","format-standard","hentry","category-the-register","tag-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>CISA: Most exploited vulnerabilities should have been eradicated decades ago 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/cisa-most-exploited-vulnerabilities-should-have-been-eradicated-decades-ago\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"CISA: Most exploited vulnerabilities should have been eradicated decades ago 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/cisa-most-exploited-vulnerabilities-should-have-been-eradicated-decades-ago\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-28T11:29:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/image.theregister.com\/246588.jpg?imageId=246588&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cisa-most-exploited-vulnerabilities-should-have-been-eradicated-decades-ago\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cisa-most-exploited-vulnerabilities-should-have-been-eradicated-decades-ago\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"CISA: Most exploited vulnerabilities should have been eradicated decades ago\",\"datePublished\":\"2026-08-28T11:29:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cisa-most-exploited-vulnerabilities-should-have-been-eradicated-decades-ago\\\/\"},\"wordCount\":728,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cisa-most-exploited-vulnerabilities-should-have-been-eradicated-decades-ago\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/image.theregister.com\\\/246588.jpg?imageId=246588&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683\",\"keywords\":[\"Security\"],\"articleSection\":[\"The Register\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cisa-most-exploited-vulnerabilities-should-have-been-eradicated-decades-ago\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cisa-most-exploited-vulnerabilities-should-have-been-eradicated-decades-ago\\\/\",\"name\":\"CISA: Most exploited vulnerabilities should have been eradicated decades ago 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cisa-most-exploited-vulnerabilities-should-have-been-eradicated-decades-ago\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cisa-most-exploited-vulnerabilities-should-have-been-eradicated-decades-ago\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/image.theregister.com\\\/246588.jpg?imageId=246588&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683\",\"datePublished\":\"2026-08-28T11:29:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cisa-most-exploited-vulnerabilities-should-have-been-eradicated-decades-ago\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cisa-most-exploited-vulnerabilities-should-have-been-eradicated-decades-ago\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cisa-most-exploited-vulnerabilities-should-have-been-eradicated-decades-ago\\\/#primaryimage\",\"url\":\"https:\\\/\\\/image.theregister.com\\\/246588.jpg?imageId=246588&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683\",\"contentUrl\":\"https:\\\/\\\/image.theregister.com\\\/246588.jpg?imageId=246588&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cisa-most-exploited-vulnerabilities-should-have-been-eradicated-decades-ago\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Security\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/security\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"CISA: Most exploited vulnerabilities should have been eradicated decades ago\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"CISA: Most exploited vulnerabilities should have been eradicated decades ago 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/cisa-most-exploited-vulnerabilities-should-have-been-eradicated-decades-ago\/","og_locale":"en_US","og_type":"article","og_title":"CISA: Most exploited vulnerabilities should have been eradicated decades ago 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/cisa-most-exploited-vulnerabilities-should-have-been-eradicated-decades-ago\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2026-08-28T11:29:00+00:00","og_image":[{"url":"https:\/\/image.theregister.com\/246588.jpg?imageId=246588&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/cisa-most-exploited-vulnerabilities-should-have-been-eradicated-decades-ago\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/cisa-most-exploited-vulnerabilities-should-have-been-eradicated-decades-ago\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"CISA: Most exploited vulnerabilities should have been eradicated decades ago","datePublished":"2026-08-28T11:29:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/cisa-most-exploited-vulnerabilities-should-have-been-eradicated-decades-ago\/"},"wordCount":728,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/cisa-most-exploited-vulnerabilities-should-have-been-eradicated-decades-ago\/#primaryimage"},"thumbnailUrl":"https:\/\/image.theregister.com\/246588.jpg?imageId=246588&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683","keywords":["Security"],"articleSection":["The Register"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/cisa-most-exploited-vulnerabilities-should-have-been-eradicated-decades-ago\/","url":"https:\/\/www.threatshub.org\/blog\/cisa-most-exploited-vulnerabilities-should-have-been-eradicated-decades-ago\/","name":"CISA: Most exploited vulnerabilities should have been eradicated decades ago 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/cisa-most-exploited-vulnerabilities-should-have-been-eradicated-decades-ago\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/cisa-most-exploited-vulnerabilities-should-have-been-eradicated-decades-ago\/#primaryimage"},"thumbnailUrl":"https:\/\/image.theregister.com\/246588.jpg?imageId=246588&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683","datePublished":"2026-08-28T11:29:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/cisa-most-exploited-vulnerabilities-should-have-been-eradicated-decades-ago\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/cisa-most-exploited-vulnerabilities-should-have-been-eradicated-decades-ago\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/cisa-most-exploited-vulnerabilities-should-have-been-eradicated-decades-ago\/#primaryimage","url":"https:\/\/image.theregister.com\/246588.jpg?imageId=246588&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683","contentUrl":"https:\/\/image.theregister.com\/246588.jpg?imageId=246588&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683"},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/cisa-most-exploited-vulnerabilities-should-have-been-eradicated-decades-ago\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Security","item":"https:\/\/www.threatshub.org\/blog\/tag\/security\/"},{"@type":"ListItem","position":3,"name":"CISA: Most exploited vulnerabilities should have been eradicated decades ago"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/61327","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=61327"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/61327\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=61327"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=61327"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=61327"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}