Top 10 Routinely Exploited Vulnerabilities
2020-05-12 • USCISA •
https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-133a
Attachments
CISA and the FBI identified ten publicly known vulnerabilities most frequently exploited by state, nonstate, and unattributed actors during 2016–2019, with Microsoft OLE flaws dominating the list. CVE-2017-11882, CVE-2017-0199, and CVE-2012-0158 were widely used across state-sponsored actors from China, Iran, North Korea, and Russia, but the alert gives no DPRK-specific attribution. It also warns of active exploitation of Pulse Secure and Citrix VPN vulnerabilities in 2020 and recommends prioritized patching, removal of end-of-life software, and stronger cloud-security configurations.