FBI, CISA, and NSA reveal top exploited vulnerabilities of 2022

Share:

In collaboration with CISA, the NSA, and the FBI, Five Eyes cybersecurity authorities have issued today a list of the 12 most exploited vulnerabilities throughout 2022.

Cybersecurity agencies in the United States, Australia, Canada, New Zealand, and the United Kingdom called on organizations worldwide to address these security flaws and deploy patch management systems to minimize their exposure to potential attacks.

Threat actors increasingly focused their attacks on outdated software vulnerabilities rather than recently disclosed ones during the previous year, specifically targeting systems left unpatched and exposed on the Internet.

“In 2022, malicious cyber actors exploited older software vulnerabilities more frequently than recently disclosed vulnerabilities and targeted unpatched, internet-facing systems,” the joint advisory reads.

“Proof of concept (PoC) code was publicly available for many of the software vulnerabilities or vulnerability chains, likely facilitating exploitation by a broader range of malicious cyber actors.”

While the Common Vulnerabilities and Exposures (CVE) Program published over 25,000 new security vulnerabilities until the end of 2022, only five vulnerabilities made it to the list of the top 12 flaws exploited in attacks the same year.

Below is the list of the 12 most exploited security flaws last year and relevant links to the National Vulnerability Database entries.

CVE Vendor Product Type
CVE-2018-13379 Fortinet FortiOS and FortiProxy SSL VPN credential exposure
CVE-2021-34473 (Proxy Shell) Microsoft Exchange Server RCE
CVE-2021-31207 (Proxy Shell) Microsoft Exchange Server Security Feature Bypass
CVE-2021-34523 (Proxy Shell) Microsoft Exchange Server Elevation of Privilege
CVE-2021-40539 Zoho ADSelfService Plus RCE/Auth Bypass
CVE-2021-26084 Atlassian Confluence Server/Data Center Arbitrary code execution
CVE-2021- 44228 (Log4Shell) Apache Log4j2 RCE
CVE-2022-22954 VMware Workspace ONE RCE
CVE-2022-22960 VMware Workspace ONE Improper Privilege Management
CVE-2022-1388 F5 Networks BIG-IP Missing Authentication
CVE-2022-30190 Microsoft Multiple Products RCE
CVE-2022-26134 Atlassian Confluence Server/Data Center RCE

The first spot goes to CVE-2018-13379, a Fortinet SSL VPN vulnerability the company fixed four years ago, in May 2019. The bug was abused by state hackers to breach U.S. government elections support systems.

Today’s advisory also highlights an additional 30 vulnerabilities often used to compromise organizations, including information on how security teams can decrease their exposure to attacks exploiting them.

To secure their systems and reduce the risk of a breach, the authoring agencies urged vendors, designers, developers, and end-user organizations to implement mitigation measures outlined in the advisory.

In June, MITRE unveiled the list of the 25 most prevalent and dangerous software weaknesses that persisted over the last two years. Two years ago, it also shared the topmost dangerous programming, design, and architecture hardware security flaws.

CISA and the FBI also released a compilation of the top 10 most exploited security flaws between 2016 and 2019.

“Organizations continue using unpatched software and systems, leaving easily discovered openings for cyber actors to target,” warned Neal Ziring, the Technical Director for NSA’s Cybersecurity Directorate.

“Older vulnerabilities can provide low-cost and high impact means for these actors to access sensitive data.”

 

(c) Lawrence Abrams

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
10:13 pm, May 31, 2025
weather icon 19°C
L: 18° | H: 20°
overcast clouds
Humidity: 75 %
Pressure: 1014 mb
Wind: 9 mph SW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 99%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:49 am
Sunset: 9:06 pm
DailyHourly
Daily ForecastHourly Forecast
Tomorrow 10:00 pm
weather icon
18° | 20°°C 0.2 mm 20% 15 mph 82 % 1015 mb 0 mm/h
Mon Jun 02 10:00 pm
weather icon
11° | 21°°C 0 mm 0% 12 mph 82 % 1019 mb 0 mm/h
Tue Jun 03 10:00 pm
weather icon
11° | 18°°C 1 mm 100% 15 mph 93 % 1013 mb 0 mm/h
Wed Jun 04 10:00 pm
weather icon
9° | 18°°C 0.48 mm 48% 12 mph 81 % 1011 mb 0 mm/h
Thu Jun 05 10:00 pm
weather icon
11° | 15°°C 1 mm 100% 16 mph 94 % 1011 mb 0 mm/h
Tomorrow 1:00 am
weather icon
15° | 18°°C 0 mm 0% 8 mph 76 % 1014 mb 0 mm/h
Tomorrow 4:00 am
weather icon
13° | 15°°C 0 mm 0% 8 mph 82 % 1015 mb 0 mm/h
Tomorrow 7:00 am
weather icon
13° | 13°°C 0 mm 0% 10 mph 75 % 1015 mb 0 mm/h
Tomorrow 10:00 am
weather icon
17° | 17°°C 0 mm 0% 11 mph 45 % 1015 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
20° | 20°°C 0 mm 0% 12 mph 37 % 1014 mb 0 mm/h
Tomorrow 4:00 pm
weather icon
20° | 20°°C 0 mm 0% 15 mph 39 % 1013 mb 0 mm/h
Tomorrow 7:00 pm
weather icon
18° | 18°°C 0.2 mm 20% 11 mph 57 % 1014 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
15° | 15°°C 0 mm 0% 8 mph 72 % 1015 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€92,377.75
0.13%
Ethereum(ETH)
€2,242.07
-1.37%
Tether(USDT)
€0.88
0.02%
XRP(XRP)
€1.94
0.19%
Solana(SOL)
€138.80
-1.70%
USDC(USDC)
€0.88
-0.01%
Dogecoin(DOGE)
€0.171447
-2.63%
Shiba Inu(SHIB)
€0.000011
-2.02%
Pepe(PEPE)
€0.000011
-7.84%
Peanut the Squirrel(PNUT)
€0.231575
-0.92%
Scroll to Top