TechNewsReel
Live

CISA: Most exploited software flaws are 'unforgivable' and decades old

A new CISA review finds that systemic organizational failures, not technical complexity, keep preventable vulnerabilities alive.

TechNewsReel Newsroom · August 28, 2026

The Cybersecurity and Infrastructure Security Agency (CISA) has revealed that the most frequently exploited software vulnerabilities are preventable weaknesses that should have been eradicated decades ago. The agency warns that the persistence of these flaws is a direct result of systemic gaps in how software is produced.

According to a review of 2024 and 2025 vulnerability data, CISA found that improper input validation (CWE-20) stands as the single most common weakness type across both the Known Exploited Vulnerability (KEV) catalog and registered Common Vulnerabilities and Exposures (CVEs). The data highlights a disturbing trend of stagnation: in 2024, seven of the 10 most frequent Common Weakness Enumerations (CWEs) on both the CVE and KEV lists were classified by MITRE as "stubborn weaknesses."

Even more critical are the "unforgivable" holes—flaws that are easily avoidable with standard security practices. CISA reported that three of the top five KEVs stemmed from these categories: improper input validation (CWE-20), path traversal (CWE-22), and OS command injections (CWE-78). Furthermore, CISA's Risk and Vulnerability Assessments (RVAs) show that memory safety and improper input validation vulnerabilities accounted for 16.7% of all KEV entries in 2025.

The Culture of Vulnerability

This data is part of a broader strategic push by CISA to promote "Secure by Design" (SBD) principles. The goal is to shift the burden of security away from the end-user and onto the software vendors. This effort draws on long-standing research, including a 2007 MITRE report on "unforgivable vulnerabilities" and a 2023 report on "stubborn weaknesses," which identify bug classes that persist not because they are hard to fix, but because of failures in development workflows.

CISA explicitly stated that the continued success of threat actors is due to these simple, preventable weaknesses remaining unaddressed. The agency noted that the problem is not one of technical complexity, but rather a reflection of "organizational culture, developer workflows, and systemic gaps in Secure by Design adoption."

Why Reactive Patching is Failing

The persistence of these flaws suggests a fundamental failure in the software industry's approach to security. By framing the issue as cultural rather than technical, CISA is signaling that the traditional model of reactive patching is unsustainable. Relying on emergency updates after a flaw is exploited creates a constant cycle of instability and risk.

Transitioning to a Secure by Design model is now viewed as critical for national security and operational resilience. By eliminating entire classes of vulnerabilities at the root, the industry can drastically reduce the overall attack surface, making it harder for adversaries to find easy entry points into critical infrastructure.

The Path Forward

CISA is calling for a paradigm shift in the industry, stating that organizations must move from reacting to threat actors to fixing the fundamental flaws those actors are known to exploit. The agency will continue to monitor the adoption of SBD practices to determine if vendors are moving toward memory-safe languages and rigorous input validation.

While the technical solutions to these "stubborn" flaws have existed for years, the industry's ability to implement them at scale remains the primary hurdle. The focus now shifts to whether software producers will prioritize structural security over rapid, insecure release cycles.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.