
Agentless security for your infrastructure and applications - to build faster, more securely and in a fraction of the operational cost of other solutions

hello@secopsolution.com
.jpg)
The cybersecurity landscape has changed dramatically over the last 12 months. Attackers are no longer waiting for organizations to fall behind—they are exploiting newly disclosed vulnerabilities within hours or days of public disclosure. Ransomware groups, nation-state actors, and financially motivated cybercriminals continue to prioritize vulnerabilities that provide immediate access to enterprise networks.
According to the CISA Known Exploited Vulnerabilities (KEV) Catalog, hundreds of vulnerabilities were confirmed to be actively exploited during the past year, affecting VPN appliances, firewalls, virtualization platforms, web applications, Microsoft products, cloud services, and networking devices. CISA added 245 new vulnerabilities to the KEV catalog during 2025, highlighting how rapidly the threat landscape continues to evolve.
This blog explores some of the most exploited CVEs from the last 12 months, why attackers targeted them, the common patterns behind successful attacks, and how organizations can better prioritize remediation.
Not every critical vulnerability becomes widely exploited.
Attackers generally look for vulnerabilities that:
These vulnerabilities often appear in:
Once exploit code becomes public, automated scanning begins almost immediately.
Critical
This vulnerability allowed attackers to extract sensitive memory contents from vulnerable NetScaler devices.
Potentially exposed data included:
Because NetScaler is commonly deployed as an organization's internet-facing VPN gateway, successful exploitation could lead to unauthorized remote access.
Security researchers observed millions of exploitation attempts shortly after disclosure, making it one of the most aggressively targeted vulnerabilities of the year.
Several SharePoint vulnerabilities continued to be heavily exploited during the past year.
Successful exploitation often resulted in:
Many ransomware operators used SharePoint as their initial access vector.
Enterprise Management Servers remained a major target.
Attackers leveraged vulnerabilities for:
Compromising endpoint management systems gives attackers centralized control over managed devices, making these platforms particularly attractive.
Virtualization infrastructure continued to be targeted because compromising a single hypervisor can expose dozens—or even hundreds—of virtual machines.
Common impacts included:
Organizations running internet-exposed management interfaces faced particularly high risk.
Privilege escalation flaws remained among the most frequently exploited vulnerabilities.
Although these bugs do not usually provide initial access, attackers often combine them with phishing or browser exploits to gain SYSTEM-level privileges.
Typical attack chain:
Initial Access → Local Privilege Escalation → Credential Dumping → Domain Compromise
Web browsers remain one of the most attacked applications.
Chrome vulnerabilities typically allowed:
Attackers frequently chained browser vulnerabilities with privilege escalation bugs to compromise endpoints.
Multiple Chrome vulnerabilities were added to the CISA KEV catalog after confirmed exploitation in the wild.
Networking infrastructure remained a high-value target.
Frequently attacked devices included:
Successful exploitation often provided:
Ivanti appliances continued attracting significant attacker attention due to their widespread enterprise deployment and exposure to the internet.
Common attack objectives included:
VPN devices remain one of the first systems attackers scan during large-scale internet campaigns.
Despite targeting different software products, attackers repeatedly followed similar workflows.
Attackers continuously scan the internet for vulnerable systems.
Once a new exploit is released, automated scanners identify exposed assets within hours.
Common entry points include:
After gaining access, attackers elevate privileges to administrator or SYSTEM level.
Common techniques include:
Attackers expand across the environment using:
Before encryption, attackers increasingly exfiltrate:
The final stage often includes:
Many organizations still prioritize patching solely by CVSS score.
However, real-world exploitation often tells a different story.
A vulnerability with:
may be significantly more dangerous than a CVSS 9.8 vulnerability with no known exploitation.
Modern vulnerability prioritization should combine:
This approach enables security teams to focus on vulnerabilities that pose the greatest real-world risk, rather than simply those with the highest severity ratings. CISA and FIRST both recommend using KEV and EPSS together for risk-based prioritization.
Several consistent trends emerged:
VPNs, firewalls, and web servers remain the highest-priority targets.
The window between vulnerability disclosure and exploitation continues to shrink.
Many attacks still exploit CVEs disclosed years ago because organizations delay patching.
Attackers increasingly aim to steal credentials rather than simply execute malicious code.
Organizations cannot patch every vulnerability immediately. Intelligent prioritization based on exploitability and business risk is essential.
Organizations should adopt a proactive vulnerability management strategy that includes:
Keeping pace with the growing number of actively exploited vulnerabilities requires more than periodic vulnerability scans. Security teams need continuous visibility, intelligent prioritization, and streamlined remediation.
SecOps Solution helps organizations strengthen their vulnerability management program by providing:
By focusing remediation efforts on vulnerabilities that are actively exploited in the wild, organizations can significantly reduce their attack surface while improving operational efficiency.
The last 12 months have demonstrated that cybercriminals are becoming faster, more automated, and increasingly selective in their exploitation efforts. Vulnerabilities affecting VPNs, firewalls, browsers, virtualization platforms, and enterprise collaboration tools have repeatedly been used to gain initial access, steal credentials, and deploy ransomware.
Relying solely on severity scores is no longer enough. Organizations that combine continuous vulnerability assessment, threat intelligence, CISA KEV, and EPSS-based prioritization are better equipped to defend against modern attacks. By implementing a risk-based vulnerability management strategy and remediating the most exploited CVEs first, security teams can dramatically reduce the likelihood of compromise and stay ahead of evolving threats.
SecOps Solution is an agentless patch and vulnerability management platform that helps organizations quickly remediate security risks across operating systems and third-party applications, both on-prem and remote.
Contact us to learn more.