WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts Vulnerability Management – Some Vulnerabilities Don’t Go Out of Style
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Vulnerability Management – Some Vulnerabilities Don’t Go Out of Style

Author: Jennifer Walker

Created: Thursday, July 29, 2021 - 17:17

Categories: Cybersecurity, Security Preparedness

A Joint Cybersecurity Advisory on the Top Routinely Exploited Vulnerabilities (AA21-209A) was released yesterday. The advisory, coauthored by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the Australian Cyber Security Centre (ACSC), the United Kingdom’s National Cyber Security Centre (NCSC), and the U.S. Federal Bureau of Investigation (FBI), highlights the top 30 vulnerabilities widely exploited during the previous 12-18 months. Additionally, the report includes specific mitigations and indicators of compromise (IoCs) to assist organizations in protecting and detecting against these top exploited vulnerabilities.

Most vulnerabilities in the top 30 have been assigned CVE (Common Vulnerabilities and Exposure) numbers and range in year of disclosure from 2021 back to 2017. The vulnerabilities are grouped by year of exploitation (2020 and 2021) and while most of the 2021 exploitation revolved around five core products (Microsoft Exchange, Pulse Connect Secure, VMware, Accellion, and Fortinet), activity during 2020 largely encompassed 2019 – 2017 vulnerabilities. This report indicates that while actors are adept at swiftly capitalizing on newly disclosed vulnerabilities, they frequently and persistently favor the old. The reason is the same for both – capitalize before patches are applied. Exploit the new ones before organizations patch and continue exploiting the old ones for organizations that still haven’t patched (and may never patch). The advisory can be accessed at CISA and an overview can be found at The Record.

Related Resources

(TLP:CLEAR) Vulnerability Notification – Active Exploitation of Check Point VPN Authentication Bypass Vulnerability, CVE-2026-50751

Jun 10, 2026 in Cybersecurity, Security Preparedness

(TLP:CLEAR) WaterISAC – EPA: National Security Information Sharing Bulletin – Q2 2026

Jun 10, 2026 in Cybersecurity, Federal & State Resources, Physical Security, Security Preparedness
Members Only

(TLP:AMBER) New IOCs (Stryker) and Malware Analysis Report (F5 BIG-IP)

Jun 5, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

Become a Member
FAQs
About
Report Incident
Traffic Light Protocol (TLP)

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar