CISA: Most Exploited Vulnerabilities Should Have Been Eradicated Decades Ago
The Register, Friday, August 28th, 2026
CISA finds the most-exploited vulnerability classes are decades old and entirely preventable.
CISA's latest review found that most exploited vulnerabilities belong to well-known, decades-old classes: injection attacks, improper input validation, and path traversal.
The agency blames organizational culture and weak adoption of Secure by Design practices rather than technical difficulty for their persistence. Seven of the top 10 common weakness types in 2024 were classified as stubborn by MITRE, three of them predating modern security awareness by nearly two decades.
CISA's message to vendors is to build software securely from the start rather than shipping ever-larger patch bundles.