WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Beyond Just the Known Exploited Vulnerabilities to the Vulnerabilities Threat Actors are Routinely Exploiting
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Beyond Just the Known Exploited Vulnerabilities to the Vulnerabilities Threat Actors are Routinely Exploiting

Author: Alec Davison

Created: Thursday, April 28, 2022 - 19:43

Categories:

On April 27, 2022, the cybersecurity authorities of the Five Eyes nations published a joint Cybersecurity Advisory (CSA), 2021 Top Routinely Exploited Vulnerabilities (AA22-117A). As in prior years, this joint effort highlights multiple vulnerabilities that threat actors are routinely exploiting – in some cases year after year – on devices and software that remain unpatched or are no longer supported by a vendor. This list, plus the larger CISA’s Known Exploited Vulnerabilities Catalog, are part of a coordinated push to help all organizations prioritize vulnerability management activities, including patching efforts that many struggle with.

The routinely exploited vulnerabilities in 2021 range in year of disclosure between 2017–2021. This report once again indicates that while actors are adept at swiftly capitalizing on newly disclosed vulnerabilities, they persistently favor old ones too. For example, CVE-2017-11882, a remote code execution bug impacting Microsoft Office (from 5 years ago), appears to be a fan favorite among threat actors as it has repeatedly made the top routinely exploited vulnerabilities over the past 3 reporting cycles. 

Full Article

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar