CVE
Security
SecOps

The Most Exploited CVEs of the Last 12 Months: Lessons Every Security Team Should Learn

Ashwani Paliwal
August 8, 2026

The cybersecurity landscape has changed dramatically over the last 12 months. Attackers are no longer waiting for organizations to fall behind—they are exploiting newly disclosed vulnerabilities within hours or days of public disclosure. Ransomware groups, nation-state actors, and financially motivated cybercriminals continue to prioritize vulnerabilities that provide immediate access to enterprise networks.

According to the CISA Known Exploited Vulnerabilities (KEV) Catalog, hundreds of vulnerabilities were confirmed to be actively exploited during the past year, affecting VPN appliances, firewalls, virtualization platforms, web applications, Microsoft products, cloud services, and networking devices. CISA added 245 new vulnerabilities to the KEV catalog during 2025, highlighting how rapidly the threat landscape continues to evolve.

This blog explores some of the most exploited CVEs from the last 12 months, why attackers targeted them, the common patterns behind successful attacks, and how organizations can better prioritize remediation.

Why Attackers Focus on Certain CVEs

Not every critical vulnerability becomes widely exploited.

Attackers generally look for vulnerabilities that:

  • Allow Remote Code Execution (RCE)
  • Require little or no authentication
  • Have publicly available exploit code
  • Affect widely deployed enterprise software
  • Can be automated for mass exploitation
  • Help establish persistence or steal credentials

These vulnerabilities often appear in:

  • VPN Gateways
  • Firewalls
  • Web Servers
  • Virtualization Platforms
  • Identity Services
  • Email Servers
  • Network Management Systems

Once exploit code becomes public, automated scanning begins almost immediately.

1. CVE-2025-5777 – Citrix NetScaler Memory Disclosure

Affected Products

  • Citrix NetScaler ADC
  • NetScaler Gateway

Severity

Critical

Why It Was Dangerous

This vulnerability allowed attackers to extract sensitive memory contents from vulnerable NetScaler devices.

Potentially exposed data included:

  • Session Tokens
  • Authentication Cookies
  • User Credentials
  • Internal Network Information

Because NetScaler is commonly deployed as an organization's internet-facing VPN gateway, successful exploitation could lead to unauthorized remote access.

Security researchers observed millions of exploitation attempts shortly after disclosure, making it one of the most aggressively targeted vulnerabilities of the year.

2. Microsoft SharePoint Remote Code Execution Vulnerabilities

Several SharePoint vulnerabilities continued to be heavily exploited during the past year.

Why Attackers Love SharePoint

  • Public-facing
  • Stores sensitive documents
  • Integrated with Active Directory
  • Often under-patched

Successful exploitation often resulted in:

  • Remote code execution
  • Credential theft
  • Web shell installation
  • Lateral movement

Many ransomware operators used SharePoint as their initial access vector.

3. Fortinet FortiClient EMS Vulnerabilities

Enterprise Management Servers remained a major target.

Attackers leveraged vulnerabilities for:

  • SQL Injection
  • Authentication bypass
  • Remote code execution

Compromising endpoint management systems gives attackers centralized control over managed devices, making these platforms particularly attractive.

4. VMware ESXi Vulnerabilities

Virtualization infrastructure continued to be targeted because compromising a single hypervisor can expose dozens—or even hundreds—of virtual machines.

Common impacts included:

  • Host takeover
  • Guest VM compromise
  • Data theft
  • Ransomware deployment

Organizations running internet-exposed management interfaces faced particularly high risk.

5. Microsoft Windows Privilege Escalation Vulnerabilities

Privilege escalation flaws remained among the most frequently exploited vulnerabilities.

Although these bugs do not usually provide initial access, attackers often combine them with phishing or browser exploits to gain SYSTEM-level privileges.

Typical attack chain:

Initial Access → Local Privilege Escalation → Credential Dumping → Domain Compromise

6. Google Chrome Zero-Day Vulnerabilities

Web browsers remain one of the most attacked applications.

Chrome vulnerabilities typically allowed:

  • Remote Code Execution
  • Sandbox Escape
  • Arbitrary Code Execution

Attackers frequently chained browser vulnerabilities with privilege escalation bugs to compromise endpoints.

Multiple Chrome vulnerabilities were added to the CISA KEV catalog after confirmed exploitation in the wild.

7. Cisco Network Device Vulnerabilities

Networking infrastructure remained a high-value target.

Frequently attacked devices included:

  • Routers
  • VPN Concentrators
  • Firewalls
  • Switch Management Interfaces

Successful exploitation often provided:

  • Persistent network access
  • Credential theft
  • Traffic interception
  • Command execution

8. Ivanti VPN Vulnerabilities

Ivanti appliances continued attracting significant attacker attention due to their widespread enterprise deployment and exposure to the internet.

Common attack objectives included:

  • Credential harvesting
  • Remote code execution
  • VPN session hijacking
  • Persistent access

VPN devices remain one of the first systems attackers scan during large-scale internet campaigns.

Common Attack Patterns Observed

Despite targeting different software products, attackers repeatedly followed similar workflows.

Internet Scanning

Attackers continuously scan the internet for vulnerable systems.

Once a new exploit is released, automated scanners identify exposed assets within hours.

Initial Access

Common entry points include:

  • VPN appliances
  • Web applications
  • Email servers
  • Firewalls

Privilege Escalation

After gaining access, attackers elevate privileges to administrator or SYSTEM level.

Credential Theft

Common techniques include:

  • LSASS dumping
  • Browser credential theft
  • Kerberos ticket extraction
  • Session cookie theft

Lateral Movement

Attackers expand across the environment using:

  • SMB
  • RDP
  • PowerShell
  • PsExec
  • Remote Management Tools

Data Theft

Before encryption, attackers increasingly exfiltrate:

  • Financial records
  • Customer databases
  • Intellectual property
  • Cloud credentials

Ransomware Deployment

The final stage often includes:

  • Encrypting servers
  • Destroying backups
  • Demanding ransom
  • Threatening public data leaks

Why CVSS Alone Isn't Enough

Many organizations still prioritize patching solely by CVSS score.

However, real-world exploitation often tells a different story.

A vulnerability with:

  • CVSS 7.5
  • Active exploitation
  • Public exploit code
  • High EPSS probability

may be significantly more dangerous than a CVSS 9.8 vulnerability with no known exploitation.

Modern vulnerability prioritization should combine:

  • CVSS
  • EPSS
  • CISA KEV status
  • Exploit availability
  • Asset criticality
  • Internet exposure
  • Business impact

This approach enables security teams to focus on vulnerabilities that pose the greatest real-world risk, rather than simply those with the highest severity ratings. CISA and FIRST both recommend using KEV and EPSS together for risk-based prioritization.

Key Lessons from the Last 12 Months

Several consistent trends emerged:

Internet-facing systems are attacked first

VPNs, firewalls, and web servers remain the highest-priority targets.

Exploitation happens rapidly

The window between vulnerability disclosure and exploitation continues to shrink.

Older vulnerabilities remain dangerous

Many attacks still exploit CVEs disclosed years ago because organizations delay patching.

Credential theft is often the real objective

Attackers increasingly aim to steal credentials rather than simply execute malicious code.

Patch prioritization matters

Organizations cannot patch every vulnerability immediately. Intelligent prioritization based on exploitability and business risk is essential.

Best Practices to Reduce Risk

Organizations should adopt a proactive vulnerability management strategy that includes:

  • Maintain a complete and accurate asset inventory.
  • Continuously scan internal, external, cloud, and remote environments.
  • Prioritize vulnerabilities using CVSS, EPSS, and CISA KEV instead of severity alone.
  • Patch internet-facing systems first.
  • Enable multi-factor authentication (MFA) on all remote access services.
  • Remove or restrict unnecessary public-facing management interfaces.
  • Monitor for indicators of compromise after high-profile CVEs are disclosed.
  • Validate that patches have been successfully deployed across all affected assets.
  • Perform regular configuration and compliance audits.
  • Integrate vulnerability management with threat intelligence to quickly identify newly exploited flaws.

How SecOps Solution Helps

Keeping pace with the growing number of actively exploited vulnerabilities requires more than periodic vulnerability scans. Security teams need continuous visibility, intelligent prioritization, and streamlined remediation.

SecOps Solution helps organizations strengthen their vulnerability management program by providing:

  • Agentless vulnerability scanning across on-premises, cloud, and hybrid environments.
  • Risk-based prioritization using CVSS, EPSS, CISA KEV, and exploit intelligence to identify the vulnerabilities that matter most.
  • Comprehensive compliance and configuration assessments to uncover security gaps beyond missing patches.
  • Actionable remediation guidance that enables IT and security teams to respond faster.
  • Continuous monitoring and reporting to track remediation progress and reduce overall cyber risk.

By focusing remediation efforts on vulnerabilities that are actively exploited in the wild, organizations can significantly reduce their attack surface while improving operational efficiency.

Conclusion

The last 12 months have demonstrated that cybercriminals are becoming faster, more automated, and increasingly selective in their exploitation efforts. Vulnerabilities affecting VPNs, firewalls, browsers, virtualization platforms, and enterprise collaboration tools have repeatedly been used to gain initial access, steal credentials, and deploy ransomware.

Relying solely on severity scores is no longer enough. Organizations that combine continuous vulnerability assessment, threat intelligence, CISA KEV, and EPSS-based prioritization are better equipped to defend against modern attacks. By implementing a risk-based vulnerability management strategy and remediating the most exploited CVEs first, security teams can dramatically reduce the likelihood of compromise and stay ahead of evolving threats.

SecOps Solution is an agentless patch and vulnerability management platform that helps organizations quickly remediate security risks across operating systems and third-party applications, both on-prem and remote.

Contact us to learn more.

Related Blogs