weaponizationcvekevvulnerability-trendsthreat-intelligence

Computer Weekly - 2024 CVEs: Few Are Weaponised

Identifies the 0.9% 'Weaponization Rate' of new CVEs and the 10% surge in legacy weaponization, supporting a risk-based prioritization model.

Summary

In the first seven-and-a-half months of 2024, newly disclosed vulnerabilities (CVEs) soared by 30% to 22,254, according to Qualys analysis. However, only 204 of these (0.9%) were successfully weaponized by threat actors, primarily targeting public-facing applications and remote services to obtain initial access. Most of these weaponized flaws appear on CISA's Known Exploited Vulnerabilities (KEV) catalog. A significant counter-trend is the 10% increase in the weaponization of old CVEs—some over six years old—highlighting a failure in enforcing security protocols for legacy software. The report advises organizations to shift from reactive patching to a predictive posture by prioritizing the 0.9% of flaws with confirmed wild exploitation over thousands of non-weaponized CVEs.

Related Checks

VULN_SLOW_REMEDIATION

The report highlights that the weaponization of old CVEs (6+ years old) has increased by 10% this year, as attackers find easy targets in neglected legacy software.

Adverse Outcome

breach via well-known exploits in legacy components that have been forgotten by the maintenance team

Because

measuring remediation speed is essential for closing the 'weaponization window' for both new zero-days and resurgent legacy flaws.

Gaps Analysis

Evidence

Out of this huge number of flaws, barely a hundredth - 204 or 0.9% - were weaponised by threat actors... subset represents the highest risk.

Blind Spot

Risk Guard evaluates technical risk but does not have a 'Weaponization Status' signal that flags when a specific CVE has been turned into a functional exploit kit.

Actionable Capability

Risk Guard would be better if it prioritized findings based on 'Active Weaponization' (e.g., presence in exploit kits or CISA KEV) rather than just CVSS severity.

← Previous Next →