Identifies the 0.9% 'Weaponization Rate' of new CVEs and the 10% surge in legacy weaponization, supporting a risk-based prioritization model.
In the first seven-and-a-half months of 2024, newly disclosed vulnerabilities (CVEs) soared by 30% to 22,254, according to Qualys analysis. However, only 204 of these (0.9%) were successfully weaponized by threat actors, primarily targeting public-facing applications and remote services to obtain initial access. Most of these weaponized flaws appear on CISA's Known Exploited Vulnerabilities (KEV) catalog. A significant counter-trend is the 10% increase in the weaponization of old CVEs—some over six years old—highlighting a failure in enforcing security protocols for legacy software. The report advises organizations to shift from reactive patching to a predictive posture by prioritizing the 0.9% of flaws with confirmed wild exploitation over thousands of non-weaponized CVEs.
The report highlights that the weaponization of old CVEs (6+ years old) has increased by 10% this year, as attackers find easy targets in neglected legacy software.
breach via well-known exploits in legacy components that have been forgotten by the maintenance team
measuring remediation speed is essential for closing the 'weaponization window' for both new zero-days and resurgent legacy flaws.
Out of this huge number of flaws, barely a hundredth - 204 or 0.9% - were weaponised by threat actors... subset represents the highest risk.
Risk Guard evaluates technical risk but does not have a 'Weaponization Status' signal that flags when a specific CVE has been turned into a functional exploit kit.
Risk Guard would be better if it prioritized findings based on 'Active Weaponization' (e.g., presence in exploit kits or CISA KEV) rather than just CVSS severity.