Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problemsiTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Recurring software weaknesses are not just a stream of separate patch tickets. CISA’s review of fiscal years 2024 and 2025 points to a two-sided problem: manufacturers need to prevent familiar defect classes in the products they build, while organizations operating those products must find exposed systems, prioritize risk, remediate, and manage unsupported technology. Secure by Design shifts some responsibility upstream; it does not replace patching, asset inventory, or incident response.
What CISA’s FY2024–2025 review is—and is not—saying
CISA presents the review as a resource for understanding vulnerability root causes and preventing recurring weaknesses. It also describes the review as a baseline for the vulnerability landscape before AI-enabled vulnerability discovery becomes more widespread. That purpose does not establish that AI caused the findings or has already changed exploitation rates.
The useful operational signal is the persistence of familiar weaknesses. CISA points to improper input validation and memory-safety issues among recurring entry points, alongside conditions that leave systems vulnerable, including poor patching and continued use of end-of-support technology. These are related problems, but not every repeated vulnerability has the same cause or remedy.
The review’s findings are qualitative here: no verified vulnerability count, percentage, or trend statistic is available to support a numerical claim. The practical value is its framing of recurring weaknesses as patterns to prevent and manage, rather than as isolated tickets alone.
#1 Best Overall
How should teams prioritize when they cannot patch everything at once?
CISA’s review describes four dimensions for prioritization. They help teams ask why one vulnerability deserves attention before another; they are not a complete scoring formula. Local asset context and remediation capacity still matter.
| Dimension | Question for the operations team |
|---|---|
| Exposure status | Is the affected asset reachable or otherwise exposed in the organization’s environment? |
| Known Exploited Vulnerability (KEV) status | Does CISA’s KEV catalog record known exploitation of the vulnerability? |
| Potential for automated exploitation | Could an attacker exploit it at scale using automation? |
| Technical impact | What could successful exploitation do to the affected system or organization? |
Read the dimensions together. A vulnerability on an exposed asset, listed in KEV, readily exploitable at scale, and capable of serious technical impact is a stronger candidate for urgent remediation than one that lacks those conditions. The framework helps order work; it does not make the decision for a team that must also account for business-critical systems, dependencies, and available staff.
Rank #2
What does an operational response look like?
The following sequence is an operational interpretation of CISA’s criteria and recommendations, not a sequence CISA prescribes verbatim. It turns the framework into a repeatable way to move from discovery to prevention.
- Establish the asset and exposure picture. Maintain an inventory that lets the team identify affected products and determine which instances are exposed. Track end-of-support systems as an explicit condition, not as an ordinary patch backlog item.
- Check exploitation evidence. Check whether the vulnerability appears in CISA’s KEV catalog, then record that status with the affected assets so the finding can inform remediation priority.
- Assess automation potential and impact. Consider whether exploitation could be automated and what a successful compromise could mean for the affected system or organization. Use these dimensions alongside exposure and KEV status, rather than treating a single signal as the whole risk picture.
- Assign remediation, verify it, and manage exceptions. Route work according to risk and capacity, verify that remediation is complete, and keep exceptions visible. For unsupported technology, determine how the organization will manage the exposure rather than assuming routine patches will remain available.
- Feed patterns upstream. When the same class of defect recurs, communicate the pattern to product owners and manufacturers. The goal is to reduce the chance that future releases reproduce it, not merely to close the current instance.
What manufacturers are expected to change
Secure by Design places greater responsibility on manufacturers to prioritize security during product development. In a January 17, 2025 release about updated joint guidance, CISA and the FBI urged software manufacturers to reduce customer risk by prioritizing security throughout the product development process.
Rank #3
The updated Product Security Bad Practices guidance is voluntary guidance aimed at software manufacturers supporting critical infrastructure, while encouraging all manufacturers to avoid the listed practices. The January 2025 update incorporated public comments and added context on memory-safe languages, KEV patching timelines, and additional bad practices. It is an upstream prevention message, not a replacement for an operator’s controls.
A March 2024 CISA and FBI alert focused on SQL injection and urged senior executives to formally review code and eliminate that vulnerability class in current and future products. The broader lesson is that a recurring defect deserves attention in development and governance processes, not only a fix in the particular release where it was found.
Rank #4
What defenders and organizational leaders still own
Operators remain responsible for knowing what they run, finding exposed systems, maintaining effective patching and vulnerability-management processes, and addressing end-of-support technology. CISA’s joint guidance on routinely exploited vulnerabilities recommends patching and vulnerability management; product design improvements cannot remove these day-to-day obligations.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
KEV status is useful beyond the federal government, but the legal scope matters. Binding Operational Directive 22-01 establishes remediation requirements for Federal Civilian Executive Branch agencies. CISA urges other organizations to prioritize KEV vulnerabilities as well, but that recommendation should not be described as a universal legal mandate. The review’s prioritization framework also references Binding Operational Directive 26-04; that is distinct from BOD 22-01 and should not be conflated with its federal KEV requirements.
Best Value
Leadership has a role in making responsibility explicit. A 2023 multi-agency advisory asks business leaders to direct teams toward eliminating recurring vulnerability classes rather than treating every new discovery only as a one-off patch. That means giving owners the authority and capacity to manage remediation, track exceptions, and raise repeated product defects to the people who can prevent them in future releases.
Quick Recap
How to use the review without overstating it
- Use the four dimensions to structure prioritization conversations, not as a substitute for asset context or a formal risk decision.
- Use recurring defect classes to inform prevention and product feedback, without assuming every recurrence has one root cause.
- Treat the review as a baseline for the period it covers; its stated purpose does not prove that AI caused the trends or changed exploitation rates.
- Keep manufacturer responsibilities and operator responsibilities connected: better-built products reduce recurring defects, while exposure management limits risk in the systems organizations already operate.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

