A multinational advisory from CISA, New Zealand’s National Cyber Security Centre and partner agencies identified the 15 vulnerabilities most routinely exploited in 2023, with more than half affecting network devices and infrastructure. Most were initially exploited as zero-days, reversing the pattern observed in 2022 and highlighting increased exploitation before public disclosure. Attackers continued to achieve the greatest success against vulnerabilities within two years of disclosure, although patching, system replacement and coordinated cybersecurity efforts reduced their usefulness. Vendor patches or fixes were available for every vulnerability listed.
Eclypsium highlighted detection gaps on network appliances, many of which cannot support endpoint detection and response agents—even when they perform security functions. Sophos firewall vulnerabilities and firmware security misconfigurations associated with the Pacific Rim attacks illustrate these risks. The agencies urged vigilant vulnerability management, while Eclypsium recommended regular patching, asset discovery, incident response planning, software supply-chain scrutiny and secure-by-design products with secure default configurations.

See which actors are running it and whether you're in range.
2 events from the most recent confirmed update back to the earliest known activity.
CISA and international partners issued an advisory identifying the top 15 vulnerabilities routinely exploited in 2023 and associated weaknesses. More than half affected network devices and infrastructure, and most were initially exploited as zero-days.
Following the Pacific Rim attacks, Eclypsium examined Sophos equipment and found disabled Intel Boot Guard on some vulnerable systems, unlocked System Management Mode and interrupt configuration, and missing BIOS write protections. These misconfigurations increased exposure to firmware-based attacks.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.