CISA Lays Vulnerability Baseline Before AI Floods the Pipeline
The review frames Secure by Design not as an aspirational slogan but as the only systemic alternative to a reactive patching model that won't scale.
TL;DR
CISA published a vulnerability review analyzing FY2024, 2025 data to establish a baseline of today's vulnerability landscape before AI-enabled discovery becomes more widespread. The review identifies common software weaknesses and shows organizations how to prioritize remediation using BOD 26-04's four criteria: exposure status, KEV catalog status, automation potential, and technical impact. The framing matters: CISA is telling organizations to fix classes of vulnerabilities systemically, not play whack-a-mole with individual CVEs.

CISA's vulnerability review, drawing on agency and open-source data from fiscal years 2024 and 2025, arrives at a finding that won't surprise anyone who's worked a SOC: most compromises don't depend on novel exploits. Threat actors scan the internet for exposed, well-known software vulnerabilities. Basic security failures do the work.
The review's purpose isn't to restate that fact but to establish a baseline while the baseline still holds. AI-enabled vulnerability discovery tools are maturing, and CISA wants organizations to understand what the landscape looks like before those tools reshape the volume and velocity of vulnerability reports. The implicit message: the current reactive-patching model, already strained, won't survive a flood.
The operational center of the review is its prioritization framework, drawn from Binding Operational Directive 26-04. Organizations are told to evaluate vulnerabilities against four criteria: whether the asset is internet-exposed, whether the vulnerability appears in CISA's Known Exploited Vulnerabilities catalog, whether exploitation can be reliably automated, and what the technical impact would be.
What the review tells software producers
The Secure by Design framing isn't decorative here. The review identifies common software weaknesses and details practices producers can use to prevent those weaknesses from recurring. The argument is systemic: fix the class of vulnerability rather than patching individual instances after discovery. For an organization staring at a backlog of CVEs, that distinction is the difference between running faster and running on a different track.
The review identifies common weaknesses and prescribes practices to prevent recurrence. It offers a method rather than a master list. For the practitioner, the takeaway is concrete: triage against BOD 26-04's four criteria. And for the software producer, the review positions Secure by Design as the hedge against a vulnerability discovery pipeline that's about to get much faster.
Published ·Deep Fathom