Top 10 Routinely Exploited Vulnerabilities

2020-05-12 USCISA

https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-133a

Attachments

AA20-133A_Top_10_Routinely_Exploited_Vulnerabilities_S508C.pdf (630 KB)

Thumbnail for Top 10 Routinely Exploited Vulnerabilities

CISA and the FBI identified ten publicly known vulnerabilities most frequently exploited by state, nonstate, and unattributed actors during 2016–2019, with Microsoft OLE flaws dominating the list. CVE-2017-11882, CVE-2017-0199, and CVE-2012-0158 were widely used across state-sponsored actors from China, Iran, North Korea, and Russia, but the alert gives no DPRK-specific attribution. It also warns of active exploitation of Pulse Secure and Citrix VPN vulnerabilities in 2020 and recommends prioritized patching, removal of end-of-life software, and stronger cloud-security configurations.

Related Reports

« Back