• CISA Releases Vulnerability Review to Help Organizations Understand and Proactively Address Software Vulnerabilities

    From CISA@cisa@messages.cisa.gov to cisa@toolazy.synchro.net on Wed Aug 26 16:06:57 2026
    --===============1934502286177495057==
    Content-Type: multipart/alternative; boundary="===============4633031928261850618=="
    MIME-Version: 1.0

    --===============4633031928261850618==
    Content-Type: text/plain; charset="utf-8"
    MIME-Version: 1.0
    Content-Transfer-Encoding: quoted-printable

    Cybersecurity and Infrastructure Security Agency (CISA)

    You are subscribed to Cybersecurity Advisories for Cybersecurity and Infras= tructure Security Agency. This information has recently been updated and is=
    now available.

    CISA Releases Vulnerability Review to Help Organizations Understand and Pro= actively Address Software Vulnerabilities [ https://www.cisa.gov/resources-= tools/resources/cisa-vulnerability-review?utm_source=3DCommsUnderPressure&u= tm_medium=3DGovDelivery ] 08/26/2026 12:00 AM EST=20

    Today, the Cybersecurity and Infrastructure Security Agency (CISA) released=
    the CISA Vulnerability Review [ https://www.cisa.gov/resources-tools/resou= rces/cisa-vulnerability-review?utm_source=3DCommsUnderPressure&utm_medium= =3DGovDelivery ] for fiscal years 2024 and 2025, offering critical insights=
    into the root causes of insecure software and practical steps organization=
    s can take to address the flaws threat actors frequently exploit. The revie=
    w establishes a baseline understanding of the current vulnerability landsca=
    pe before AI-enabled vulnerability discovery becomes more widespread. It em= phasizes the importance of Secure by Design [ https://www.cisa.gov/secureby= design ] principles in shifting software cybersecurity efforts from reactiv=
    e response to proactive risk management=E2=80=94backed by public-private se= ctor collaboration and leadership support that recognizes cyber risk as a b= usiness risk and national security issue. The review also highlights how or= ganizations can prioritize vulnerabilities for action by using the framewor=
    k outlined in Binding Operational Directive 26-04: Prioritizing Security Ba= sed on Risk [ https://www.cisa.gov/news-events/directives/bod-26-04-priorit= izing-security-updates-based-risk ], which evaluates exposure status, known=
    exploited vulnerability (KEV) [ https://www.cisa.gov/known-exploited-vulne= rabilities-catalog ] status, potential for exploitation to be automated, an=
    d technical impact.

    Key findings include:


    * Many threat actors scan for and exploit simple, known vulnerabilities r= ather than relying on advanced techniques.=20
    * Improper input validation and memory safety vulnerabilities are the mos=
    t reliable entry points for threat actors and are frequently targeted.=20
    * Basic security failures, like poor patching and continued use of end-of= -support technology, significantly contribute to compromise.=20
    * Emerging technology, such as AI, introduces efficiencies threat actors = can leverage to automate and scale threat activity.=20

    Organizations should focus on eliminating persistent and preventable weakne= sses, prioritize remediation of KEVs [ https://www.cisa.gov/known-exploited= -vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerab= ilities ] and exposed assets, adopt Secure by Design principles, and levera=
    ge CISA=E2=80=99s no-cost resources [ https://www.cisa.gov/resources-tools =
    ], services and tools [ https://www.cisa.gov/resources-tools/resources/no-c= ost-cybersecurity-services-and-tools ] to help identify and reduce risk.

    Read the CISA Vulnerability Review [ https://www.cisa.gov/resources-tools/r= esources/cisa-vulnerability-review?utm_source=3DCommsUnderPressure&utm_medi= um=3DGovDelivery ] to review the full analysis and recommendations.



    * Additional Resources:
    CISA=E2=80=99s Cross=E2=80=91Sector Cybersecurity Performance Goals (CPGs) = 2.0 [ https://www.cisa.gov/cross-sector-cybersecurity-performance-goals/cro= ss-sector-cybersecurity-performance-goals ]=E2=80=94a prioritized, outcome= =E2=80=91focused baseline that maps to NIST CSF 2.0.=20
    * Stakeholder=E2=80=91Specific Vulnerability Categorization (SSVC) [ http= s://www.cisa.gov/resources-tools/resources/stakeholder-specific-vulnerabili= ty-categorization-ssvc ]=E2=80=94decisioning to focus remediation on what m= atters: exposure, KEV status, exploit automation, and technical impact.=20
    * Internet Exposure Reduction Guidance [ https://www.cisa.gov/resources-t= ools/resources/exposure-reduction ]=E2=80=94practical steps to find and clo=
    se exposed services quickly.=20
    * Vulnrichment Program [ https://www.cisa.gov/resources-tools/programs/vu= lnrichment-program ]=E2=80=94machine=E2=80=91readable signals on KEV/exploi= tation that help you automate patch prioritization.=20
    * Risk & Vulnerability Assessments (RVAs) [ https://www.cisa.gov/resource= s-tools/resources/risk-and-vulnerability-assessments ]=E2=80=94on=E2=80=91s= ite penetration tests that reveal how real=E2=80=91world cyber threat actor=
    s could exploit persistent weaknesses in an organization=E2=80=99s environm= ent and provide clear, actionable steps to reduce those risks.=20

    * Cyber Hygiene (CyHy) Scanning [ https://www.cisa.gov/cyber-hygiene-serv= ices ]=E2=80=94no=E2=80=91cost services to quantify and reduce risk across = external attack surfaces.=20

    Please share your thoughts with us through this anonymous survey [ https://= cisasurvey.gov1.qualtrics.com/jfe/form/SV_9n4TtB8uttUPaM6?Source=3DGovDeliv= eryCISAVulnReviewFY2425 ]. We appreciate your feedback.

    This product is provided subject to this Notification [ https://www.cisa.go= v/notification ] and this Privacy & Use [ https://www.cisa.gov/privacy-poli=
    cy ] policy.

    body { font-size: 1em; font-family: Arial, Verdana, sans-serif; font-weight=
    : normal; font-style: normal; color: #333333; }=20

    Having trouble viewing this message?=C2=A0View it as a webpage [ https://co= ntent.govdelivery.com/accounts/USDHSCISA/bulletins/426df53 ].=C2=A0 [ https= ://content.govdelivery.com/accounts/USDHS/bulletins/292141e ]

    You are subscribed to updates from the Cybersecurity and Infrastructure Sec= urity Agency [ https://www.cisa.gov ] (CISA)
    Manage Subscriptions [ https://public.govdelivery.com/accounts/USDHSCISA/su= bscriber/edit?preferences=3Dtrue#tab1 ]=C2=A0=C2=A0|=C2=A0=C2=A0Privacy Pol= icy [ https://www.cisa.gov/privacy-policy ]=C2=A0=C2=A0|=C2=A0 Help [ https= ://subscriberhelp.granicus.com/s/article/Subscriber-Help-Center ] [ https:/= /insights.govdelivery.com/Communications/Subscriber_Help_Center ]

    Connect with CISA:=20
    Facebook [ https://www.facebook.com/CISA ]=C2=A0 |=C2=A0 Twitter [ https://= twitter.com/CISAgov ]=C2=A0 |=C2=A0 Instagram [ https://Instagram.com/cisag=
    ov ]=C2=A0 |=C2=A0 LinkedIn [ https://www.linkedin.com/company/cybersecurit= y-and-infrastructure-security-agency ]=C2=A0 |=C2=A0=C2=A0 YouTube [ https:= //www.youtube.com/channel/UCxyq9roe-npgzrVwbpoAy0A ]

    ________________________________________________________________________


    This email was sent to cisa@toolazy.synchro.net using Granicus Communicatio=
    ns Cloud, on behalf of: Cybersecurity and Infrastructure Security Agency = =C2=B7 707 17th St, Suite 4000 =C2=B7 Denver, CO 80202 Granicus Communicati= ons logo [ https://granicus.com/solution/digital-communication-engagement/ = ]=20
    body .abe-column-block { min-height: 5px; } table.gd_combo_table img {margi= n-left:10px; margin-right:10px;} table.gd_combo_table div.govd_image_displa=
    y img, table.gd_combo_table td.gd_combo_image_cell img {margin-left:0px; ma= rgin-right:0px;}

    --===============4633031928261850618==
    Content-Type: text/html; charset="utf-8"
    MIME-Version: 1.0
    Content-Transfer-Encoding: quoted-printable

    <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
    "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
    <html xmlns=3D"http://www.w3.org/1999/xhtml" xml:lang=3D"en" lang=3D"en"> <head>
    <title> CISA Releases Vulnerability Review to Help Organizations Underst= and and Proactively Address Software Vulnerabilities
    </title>


    </head>
    <body style=3D"">

    <table width=3D"700" border=3D"0" cellspacing=3D"0" cellpadding=3D"0"=
    align=3D"center">
    <tr>
    <td>

    <!--[if (gte mso 9)|(IE)]>
    <table style=3D"display:none"><tr><td><a name=3D"gd_top" id=3D"gd_top"></= a></td></tr></table>
    <![endif]-->
    <a name=3D"gd_top" id=3D"gd_top"></a>

    =20



    <p><img src=3D"https://content.govdelivery.com/attachments/fancy_images/U= SDHSCISA/2020/06/3486054/05152023-gov-delivery-banner-copy_original.png" al= t=3D"Cybersecurity and Infrastructure Security Agency (CISA)" title=3D"" wi= dth=3D"600" height=3D"100"></p>
    <p>You are subscribed to Cybersecurity Advisories for Cybersecurity and I= nfrastructure Security Agency. This information has recently been updated a=
    nd is now available.</p>
    <div class=3D"rss_item" style=3D"margin-bottom: 2em;">
    <div class=3D"rss_title" style=3D"font-weight: bold; font-size: 120%; margi=
    n: 0 0 0.3em; padding: 0;"><a href=3D"https://www.cisa.gov/resources-tools/= resources/cisa-vulnerability-review?utm_source=3DCommsUnderPressure&utm_med= ium=3DGovDelivery" target=3D"_blank" title=3D"CISA Releases Vulnerability R= eview to Help Organizations Understand and Proactively Address Software Vul= nerabilities" rel=3D"noopener">CISA Releases Vulnerability Review to Help O= rganizations Understand and Proactively Address Software Vulnerabilities</a= ></div>
    <div class=3D"rss_pub_date" style=3D"font-size: 90%; font-style: italic; co= lor: #666666; margin: 0 0 0.3em; padding: 0;">08/26/2026 12:00 AM EST</div> <div class=3D"l-page-section l-page-section--rich-text csaf-imported">

    <div class=3D"l-constrain">
    <div class=3D"l-page-section__content">
    <p>Today, the Cybersecurity and Infrastructure Security Agency (CISA) relea= sed the <a href=3D"https://www.cisa.gov/resources-tools/resources/cisa-vuln= erability-review?utm_source=3DCommsUnderPressure&utm_medium=3DGovDelivery" = target=3D"_blank" title=3D"CISA Vulnerability Review" rel=3D"noopener">CISA=
    Vulnerability Review</a> for fiscal years 2024 and 2025, offering critical=
    insights into the root causes of insecure software and practical steps org= anizations can take to address the flaws threat actors frequently exploit. = The review establishes a baseline understanding of the current vulnerabilit=
    y landscape before AI-enabled vulnerability discovery becomes more widespre= ad. It emphasizes the importance of <a href=3D"https://www.cisa.gov/secureb= ydesign" target=3D"_blank" title=3D"Secure by Design" rel=3D"noopener">Secu=
    re by Design</a> principles in shifting software cybersecurity efforts from=
    reactive response to proactive risk management=E2=80=94backed by public-pr= ivate sector collaboration and leadership support that recognizes cyber ris=
    k as a business risk and national security issue. The review also highlight=
    s how organizations can prioritize vulnerabilities for action by using the = framework outlined in <a href=3D"https://www.cisa.gov/news-events/directive= s/bod-26-04-prioritizing-security-updates-based-risk" target=3D"_blank" tit= le=3D"Binding Operational Directive 26-04: Prioritizing Security Based on R= isk" rel=3D"noopener">Binding Operational Directive 26-04: Prioritizing Sec= urity Based on Risk</a>, which evaluates exposure status, <a href=3D"https:= //www.cisa.gov/known-exploited-vulnerabilities-catalog" target=3D"_blank" t= itle=3D"known exploited vulnerability (KEV)" rel=3D"noopener">known exploit=
    ed vulnerability (KEV)</a> status, potential for exploitation to be automat= ed, and technical impact.</p>
    <p>Key findings include:</p>

    <li>Many threat actors scan for and exploit simple, known vulnerabilities r= ather than relying on advanced techniques.</li>
    <li>Improper input validation and memory safety vulnerabilities are the mos=
    t reliable entry points for threat actors and are frequently targeted.</li> <li>Basic security failures, like poor patching and continued use of end-of= -support technology, significantly contribute to compromise.</li>
    <li>Emerging technology, such as AI, introduces efficiencies threat actors = can leverage to automate and scale threat activity.</li>
    </ul>
    <p>Organizations should focus on eliminating persistent and preventable wea= knesses, prioritize <a href=3D"https://www.cisa.gov/known-exploited-vulnera= bilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities"=
    target=3D"_blank" title=3D"remediation of KEVs" rel=3D"noopener">remediati=
    on of KEVs</a> and exposed assets, adopt Secure by Design principles, and l= everage CISA=E2=80=99s no-cost <a href=3D"https://www.cisa.gov/resources-to= ols" target=3D"_blank" title=3D"resources" rel=3D"noopener">resources</a>, =
    <a href=3D"https://www.cisa.gov/resources-tools/resources/no-cost-cybersecu= rity-services-and-tools" target=3D"_blank" title=3D"services and tools" rel= =3D"noopener">services and tools</a> to help identify and reduce risk.</p> <p><br>Read the <a href=3D"https://www.cisa.gov/resources-tools/resources/c= isa-vulnerability-review?utm_source=3DCommsUnderPressure&utm_medium=3DGovDe= livery" target=3D"_blank" title=3D"CISA Vulnerability Review" rel=3D"noopen= er">CISA Vulnerability Review</a> to review the full analysis and recommend= ations.</p>

    <li>Additional Resources:<br>CISA=E2=80=99s <a href=3D"https://www.cisa.gov= /cross-sector-cybersecurity-performance-goals/cross-sector-cybersecurity-pe= rformance-goals" target=3D"_blank" title=3D"Cross=E2=80=91Sector Cybersecur= ity Performance Goals (CPGs) 2.0" rel=3D"noopener">Cross=E2=80=91Sector Cyb= ersecurity Performance Goals (CPGs) 2.0</a>=E2=80=94a prioritized, outcome= =E2=80=91focused baseline that maps to NIST CSF 2.0.</li>

    <a href=3D"https://www.cisa.gov/resources-tools/resources/stakeholder-speci= fic-vulnerability-categorization-ssvc" target=3D"_blank" title=3D"Stakehold= er=E2=80=91Specific Vulnerability Categorization (SSVC)" rel=3D"noopener">S= takeholder=E2=80=91Specific Vulnerability Categorization (SSVC)</a>=E2=80= =94decisioning to focus remediation on what matters: exposure, KEV status, = exploit automation, and technical impact.</li>

    <a href=3D"https://www.cisa.gov/resources-tools/resources/exposure-reductio=
    n" target=3D"_blank" title=3D"Internet Exposure Reduction Guidance" rel=3D"= noopener">Internet Exposure Reduction Guidance</a>=E2=80=94practical steps =
    to find and close exposed services quickly.</li>

    <a href=3D"https://www.cisa.gov/resources-tools/programs/vulnrichment-progr= am" target=3D"_blank" title=3D"Vulnrichment Program" rel=3D"noopener">Vulnr= ichment Program</a>=E2=80=94machine=E2=80=91readable signals on KEV/exploit= ation that help you automate patch prioritization.</li>

    <a href=3D"https://www.cisa.gov/resources-tools/resources/risk-and-vulnerab= ility-assessments" target=3D"_blank" title=3D"Risk &amp; Vulnerability Asse= ssments (RVAs)" rel=3D"noopener">Risk &amp; Vulnerability Assessments (RVAs= )</a>=E2=80=94on=E2=80=91site penetration tests that reveal how real=E2=80= =91world cyber threat actors could exploit persistent weaknesses in an orga= nization=E2=80=99s environment and provide clear, actionable steps to reduc=
    e those risks.</li>

    <a href=3D"https://www.cisa.gov/cyber-hygiene-services" target=3D"_blank" t= itle=3D"Cyber Hygiene (CyHy) Scanning" rel=3D"noopener">Cyber Hygiene (CyHy=
    ) Scanning</a>=E2=80=94no=E2=80=91cost services to quantify and reduce risk=
    across external attack surfaces.</li>
    </ol>
    <p>Please share your thoughts with us through this <a href=3D"https://cisas= urvey.gov1.qualtrics.com/jfe/form/SV_9n4TtB8uttUPaM6?Source=3DGovDeliveryCI= SAVulnReviewFY2425" target=3D"_blank" title=3D"anonymous survey" rel=3D"noo= pener">anonymous survey</a>. We appreciate your feedback.</p>
    <p>This product is provided subject to this <span><span style=3D"color: #46= 7886;"><a href=3D"https://www.cisa.gov/notification" target=3D"_blank" titl= e=3D"Notification" rel=3D"noopener">Notification</a></span></span> and this=
    <span><span style=3D"color: #467886;"><a href=3D"https://www.cisa.gov/priv= acy-policy" target=3D"_blank" title=3D"Privacy &amp; Use" rel=3D"noopener">= Privacy &amp; Use</a></span></span> policy.<span style=3D"font-size: 11.0pt= ;"></span></p>
    </div>
    </div>
    </div>
    </div>
    <style>body {
    font-size: 1em; font-family: Arial, Verdana, sans-serif; font-weight: norma=
    l; font-style: normal; color: #333333;
    }
    </style>
    =20


    <div id=3D"mail_footer">
    <p style=3D"text-align: center;"><span style=3D"font-size: 10.0pt; colo=
    r: #757575;">Having trouble viewing this message?=C2=A0</span><a href=3D"ht= tps://content.govdelivery.com/accounts/USDHSCISA/bulletins/426df53" target= =3D"_blank" rel=3D"noopener">View it as a webpage</a>.=C2=A0<a href=3D"http= s://content.govdelivery.com/accounts/USDHS/bulletins/292141e" target=3D"_bl= ank" rel=3D"noopener"></a><span style=3D"font-size: 10.0pt; color: #757575;= "></span></p>
    <p style=3D"text-align: center;"><span style=3D"font-size: 10.0pt; color: #= 757575;">You are subscribed to updates from the </span><a href=3D"https://w= ww.cisa.gov"><span style=3D"font-size: 10.0pt;">Cybersecurity and Infrastru= cture Security Agency</span></a><span style=3D"font-size: 10.0pt; color: #7= 57575;"> (CISA)<br></span><a href=3D"https://public.govdelivery.com/account= s/USDHSCISA/subscriber/edit?preferences=3Dtrue#tab1" target=3D"_blank" rel= =3D"noopener"><span style=3D"font-size: 10.0pt; color: #00568c;">Manage Sub= scriptions</span></a>=C2=A0=C2=A0<span style=3D"font-size: 10.0pt; color: #= 757575;">|=C2=A0=C2=A0</span><a href=3D"https://www.cisa.gov/privacy-policy=
    " target=3D"_blank" rel=3D"noopener"><span style=3D"font-size: 10.0pt; colo=
    r: #00568c;">Privacy Policy</span></a><span style=3D"font-size: 10.0pt; col= or: #757575;">=C2=A0=C2=A0|=C2=A0 <a href=3D"https://subscriberhelp.granicu= s.com/s/article/Subscriber-Help-Center" target=3D"_blank" rel=3D"noopener">= Help</a><a href=3D"https://insights.govdelivery.com/Communications/Subscrib= er_Help_Center" target=3D"_blank" rel=3D"noopener"></a></span><span style= =3D"font-size: 10.0pt; color: #757575;"></span></p>
    <p style=3D"text-align: center;"><span style=3D"font-size: 10.0pt; color: #= 757575;">Connect with CISA: <br></span><a href=3D"https://www.facebook.com/= CISA" target=3D"_blank" rel=3D"noopener"><span style=3D"font-size: 10.0pt; = color: #00568c;">Facebook</span></a><span style=3D"font-size: 10.0pt; color=
    : #757575;">=C2=A0 |=C2=A0 </span><a href=3D"https://twitter.com/CISAgov" t= arget=3D"_blank" rel=3D"noopener"><span style=3D"font-size: 10.0pt; color: = #00568c;">Twitter</span></a><span style=3D"font-size: 10.0pt; color: #75757= 5;">=C2=A0 |=C2=A0 </span><a href=3D"https://Instagram.com/cisagov" target= =3D"_blank" rel=3D"noopener"><span style=3D"font-size: 10.0pt; color: #0056= 8c;">Instagram</span></a><span style=3D"font-size: 10.0pt; color: #757575;"= >=C2=A0 |=C2=A0 </span><a href=3D"https://www.linkedin.com/company/cybersec= urity-and-infrastructure-security-agency" target=3D"_blank" rel=3D"noopener= "><span style=3D"font-size: 10.0pt; color: #00568c;">LinkedIn</span></a><sp=
    an style=3D"font-size: 10.0pt; color: #757575;">=C2=A0 |=C2=A0=C2=A0 </span= ><a href=3D"https://www.youtube.com/channel/UCxyq9roe-npgzrVwbpoAy0A" targe= t=3D"_self"><span style=3D"font-size: 10.0pt; color: #00568c;">YouTube</spa= n></a><span style=3D"font-size: 10.0pt; color: #757575;"></span></p>

    </div>
    <div id=3D"tagline">
    <hr>
    <table style=3D"width: 100%;" border=3D"0" cellspacing=3D"0" cellpadding=3D=

    <tbody>

    <td style=3D"color: #757575; font-size: 10px; font-family: Arial;" width=3D= "89%">This email was sent to cisa@toolazy.synchro.net using Granicus Commun= ications Cloud, on behalf of: Cybersecurity and Infrastructure Security Age= ncy =C2=B7 707 17th St, Suite 4000 =C2=B7 Denver, CO 80202</td>
    <td align=3D"right" width=3D"11%"><a href=3D"https://granicus.com/solution/= digital-communication-engagement/" target=3D"_blank" rel=3D"noopener"><img = src=3D"https://content.govdelivery.com/images/govd-logo-dark.png" border=3D= "0" alt=3D"Granicus Communications logo" width=3D"115"></a></td>

    </tr>
    </tbody>
    </table>
    <style type=3D"text/css">body .abe-column-block { min-height: 5px; } table.= gd_combo_table img {margin-left:10px; margin-right:10px;} table.gd_combo_ta= ble div.govd_image_display img, table.gd_combo_table td.gd_combo_image_cell=
    img {margin-left:0px; margin-right:0px;}</style>

    </div>
    </td>
    </tr>
    </table>

    <img alt=3D"" src=3D"https://links-2.govdelivery.com/CI0/010101a03ed318eb-6= 5af4f04-d276-4fe7-b33a-a7d354edaeb9-000000/_nm9OwsJ6BG3Theda_WqoW0Pcbxw7vOS= tooKBHAhDcU=3D452" style=3D"display: none; width: 1px; height: 1px;">
    </body>
    </html>

    --===============4633031928261850618==--

    --===============1934502286177495057==--