Vulnerability
CISA Warns: Decades-Old Vulnerabilities Remain Primary Targets for Hackers
A new report from CISA reveals that the most exploited vulnerabilities today are often legacy issues that should have been patched years ago.
The Persistence of Legacy Security Gaps
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a stern warning regarding the current state of global cybersecurity. Their latest findings suggest that a significant majority of actively exploited vulnerabilities in the wild are not 'zero-days' or cutting-edge exploits, but rather legacy flaws that have been known to the security community for years, and in some cases, decades. This 'sorry state of affairs' is attributed to a combination of stagnant organizational cultures, technical debt, and a systemic failure to adopt 'Secure by Design' principles.
The report indicates that while new vulnerabilities receive the most media attention, threat actors prefer the path of least resistance. Using well-documented exploits against unpatched systems is cost-effective and highly successful. This highlights a massive gap between the availability of patches and their actual implementation within enterprise networks. Organizations often struggle to balance the need for uptime with the necessity of patching, leading to prolonged exposure to known risks.
Closing the Window of Exposure
It is no longer acceptable to treat patching as a secondary IT task. Organizations must elevate vulnerability management to a core strategic priority. To address these systemic gaps, we recommend the following actions:
- Adopt a 'Secure by Design' Framework: When procuring new software or hardware, prioritize vendors that demonstrate a commitment to built-in security. Shift the burden of security from the end-user back to the manufacturer.
- Prioritize the KEV Catalog: Utilize CISA’s Known Exploited Vulnerabilities (KEV) catalog to prioritize patching efforts. If a vulnerability is being actively exploited in the wild, it must be addressed immediately, regardless of its perceived severity score in isolation.
- Decommission End-of-Life (EoL) Systems: Legacy systems that no longer receive security updates are ticking time bombs. Organizations must develop a roadmap to replace or isolate these systems using network segmentation to prevent them from becoming an easy entry point for attackers.
แหล่งที่มา: The Register - Security เผยแพร่ครั้งแรก: Fri, 28 Aug 2026 13:29:00 +0200 บทความต้นฉบับ: อ่านต้นฉบับ
Source Attribution
แหล่งที่มา: The Register - Security
เผยแพร่ครั้งแรก: Fri, 28 Aug 2026 13:29:00 +0200
บทความต้นฉบับ: https://www.theregister.com/security/2026/08/28/cisa-most-exploited-vulnerabilities-should-have-been-eradicated-decades-ago/5293194
* Facebook / LinkedIn ไม่อนุญาตให้ใส่ข้อความให้ล่วงหน้า — กดปุ่มจะคัดลอกข้อความให้ก่อน เปิดหน้าแชร์แล้ววาง (paste) ได้เลย พรีวิวการ์ดจะแสดงอัตโนมัติเมื่อวางลิงก์
