Three of the ten most exploited weaknesses were called unforgivable in 2007
2026-09-01Security
CISA's review of 2024 and 2025 finds that the flaws attackers actually use are injection, input validation and path traversal — the same list as two decades ago. Seven of the ten most frequent weaknesses on the exploited-vulnerabilities catalog account for 41.5% of everything on it. CISA blames culture and workflow, not difficulty.