🔧 AI Nachrichten Major AI platforms go down in unprecedented simultaneous outage(03.09.2026 um 17:34 Uhr)
🔧 AI Nachrichten ChatGPT, Claude, and Grok Down? Users Report Widespread Outages(03.09.2026 um 19:14 Uhr)
🔧 AI Nachrichten OpenAI Launches GPT-6 Astra, Says We May Have Entered the AGI Era(03.09.2026 um 22:08 Uhr)
🔧 AI Nachrichten Claude Comes to CarPlay as Fifth Major AI Chatbot App(05.09.2026 um 05:31 Uhr)
🔧 AI Nachrichten OpenAI’s GPT-6 Astra Is AGI, Says NVIDIA CEO Jensen Huang(07.09.2026 um 06:31 Uhr)
🔧 AI Nachrichten Blame AI companies for Mac mini and Mac Studio shortage(31.08.2026 um 10:32 Uhr)
🔧 AI Nachrichten Major AI platforms go down in unprecedented simultaneous outage(03.09.2026 um 17:34 Uhr)
🔧 AI Nachrichten ChatGPT, Claude, and Grok Down? Users Report Widespread Outages(03.09.2026 um 19:14 Uhr)
🔧 AI Nachrichten OpenAI Launches GPT-6 Astra, Says We May Have Entered the AGI Era(03.09.2026 um 22:08 Uhr)
🔧 AI Nachrichten Claude Comes to CarPlay as Fifth Major AI Chatbot App(05.09.2026 um 05:31 Uhr)
🔧 AI Nachrichten OpenAI’s GPT-6 Astra Is AGI, Says NVIDIA CEO Jensen Huang(07.09.2026 um 06:31 Uhr)
🔧 AI Nachrichten Blame AI companies for Mac mini and Mac Studio shortage(31.08.2026 um 10:32 Uhr)

🕵️ Sicherheitslücken 🕛 kürzlich 27 Min Lesezeit CVE-2017-6742
0

2023 Top Routinely Exploited Vulnerabilities

Cyber Threat & Vulnerability Dossier CVSS 9.8 CRITICAL (Heuristik) EPSS 82%
ANGRIPPSVEKTOR
💻 Lokal
AUTHENTIFIZIERUNG
🔑 Geringe Nutzerrechte nötig
SCHADENSPROFIL
🗄️ Daten-Exfiltration (SQLi) / Full Compromise
CWE-KLASSIFIZIERUNG
CWE-89: SQL Injection
Handlungsempfehlung: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
Im CVE-Radar öffnen
↗ Quelle (cisa.gov)
🗣️ Stimme:
📑 Inhaltsübersicht

Summary


The following cybersecurity agencies coauthored this joint Cybersecurity Advisory (hereafter collectively referred to as the authoring agencies):



  • United States: The Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and National Security Agency (NSA)

  • Australia: Australian Signals Directorate’s Australian Cyber Security Centre (ACSC)

  • Canada: Canadian Centre for Cyber Security (CCCS)

  • New Zealand: New Zealand National Cyber Security Centre (NCSC-NZ) and Computer Emergency Response Team New Zealand (CERT NZ)

  • United Kingdom: National Cyber Security Centre (NCSC-UK)


This advisory provides details, collected and compiled by the authoring agencies, on the Common Vulnerabilities and Exposures (CVEs) routinely and frequently exploited by malicious cyber actors in 2023 and their associated Common Weakness Enumerations (CWEs). Malicious cyber actors exploited more zero-day vulnerabilities to compromise enterprise networks in 2023 compared to 2022, allowing them to conduct operations against high priority targets.


The authoring agencies strongly encourage vendors, designers, developers, and end-user organizations to implement the following recommendations, and those found within the Mitigations section of this advisory, to reduce the risk of compromise by malicious cyber actors.



  • Vendors, designers, and developers. Implement
    (PDF, 907.24 KB
    )



Technical Details


Key Findings


In 2023, malicious cyber actors exploited more zero-day vulnerabilities to compromise enterprise networks compared to 2022, allowing them to conduct cyber operations against higher-priority targets. In 2023, the majority of the most frequently exploited vulnerabilities were initially exploited as a zero-day, which is an increase from 2022, when less than half of the top exploited vulnerabilities were exploited as a zero-day. 


Malicious cyber actors continue to have the most success exploiting vulnerabilities within two years after public disclosure of the vulnerability. The utility of these vulnerabilities declines over time as more systems are patched or replaced. Malicious cyber actors find less utility from zero-day exploits when international cybersecurity efforts reduce the lifespan of zero-day vulnerabilities.


Cybersecurity Efforts to Include


Implementing security-centered product development lifecycles. Software developers deploying patches to fix software vulnerabilities is often a lengthy and expensive process, particularly for zero-days. The use of more robust testing environments and implementing threat modeling throughout the product development lifecycle will likely reduce overall product vulnerabilities.


Increasing incentives for responsible vulnerability disclosure. Global efforts to reduce barriers to responsible vulnerability disclosure could restrict the utility of zero-day exploits used by malicious cyber actors. For example, instituting vulnerability reporting bug bounty programs that allow researchers to receive compensation and recognition for their contributions to vulnerability research may boost disclosures.


Using sophisticated endpoint detection and response (EDR) tools. End users leveraging EDR solutions may improve the detection rate of zero-day exploits. Most zero-day exploits, including at least three of the top 15 vulnerabilities from last year, have been discovered when an end user or EDR system reports suspicious activity or unusual device malfunctions.


Top Routinely Exploited Vulnerabilities


Listed in Table 1 are the top 15 vulnerabilities the authoring agencies observed malicious cyber actors routinely exploiting in 2023 with details also discussed below.



  • : This vulnerability affects Citrix NetScaler ADC and NetScaler Gateway.

    • Allows session token leakage; a proof-of-concept for this exploit was revealed in October 2023.



  • This vulnerability affects Cisco IOS XE, following activity from CVE-2023-20198.

    • Allows privilege escalation, once a local user has been created, to root privileges.



  • : This vulnerability affects Progress MOVEit Transfer.

    • Allows abuse of an SQL injection vulnerability to obtain a sysadmin API access token.

    • Allows a malicious cyber actor to obtain remote code execution via this access by abusing a deserialization call.



  • : This vulnerability, known as Log4Shell, affects Apache’s Log4j library, an open source logging framework incorporated into thousands of products worldwide.

    •  Allows the execution of arbitrary code.

      • An actor can exploit this vulnerability by submitting a specially crafted request to a vulnerable system, causing the execution of arbitrary code.

      • The request allows a cyber actor to take full control of a system.

      • The actor can then steal information, launch ransomware, or conduct other malicious activity.

      • Malicious cyber actors began exploiting the vulnerability after it was publicly disclosed in December 2021.





  • : This is an unauthenticated remote code execution vulnerability that affects multiple products using Zoho ManageEngine.

    • Allows an unauthenticated user to execute arbitrary code by providing a crafted samlResponse XML to the ServiceDesk Plus SAML endpoint.



  • : This vulnerability affects Microsoft Netlogon.

    • Allows privilege escalation.

      • An unauthorized user may use non-default configurations to establish a vulnerable Netlogon secure channel connection to a domain controller by using the Netlogon Remote Protocol.
        Note: This CVE has been included in top routinely exploited vulnerabilities lists since 2021.





  • : This vulnerability affects Microsoft Office Outlook.

    • Allows elevation of privilege.

      • A threat actor can send a specially crafted email that the Outlook client will automatically trigger when Outlook processes it.

      • This exploit occurs even without user interaction.






  • Citrix

    NetScaler ADC 


    NetScaler Gateway



    Code Injection

    Citrix

    NetScaler ADC 


    NetScaler Gateway



    Buffer Overflow

    Cisco
    IOS XE Web UI
    Privilege Escalation

    Cisco
    IOS XE
    Web UI Command Injection

    Fortinet

    FortiOS 


    FortiProxy SSL-VPN



    Heap-Based Buffer Overflow















    Barracuda Networks
    ESG Appliance
    Improper Input Validation



















    ownCloud
    graphapi
    Information Disclosure

    Atlassian 
    Confluence Data Center and Server 
    Improper Authorization

    Novi
    Novi Survey
    Insecure Deserialization
     
    FatPipe 
    WARP, IPVPN, and MPVPN 
    Configuration Upload Exploit
     
    Zoho 
    ManageEngine ADSelfService Plus 
    Authentication Bypass

    Fortra 
    GoAnywhere MFT 
    RCE

    F5 
    BIG-IP and BIG-IQ Centralized Management iControl REST 
    RCE

    Microsoft 
    Remote Desktop Services
    RCE

    Fortinet 
    FortiOS SSL VPN 
    Path Traversal
     
    Netwrix 
    Auditor 
    Insecure Object Deserialization
     
    Ivanti 
    Endpoint Manager Mobile 
    Authentication Bypass
     
    Ivanti 
    Endpoint Manager Mobile (EPMM) 
    Path Traversal
     
    N/A
    HTTP/2 
    Rapid Reset Attack

    Juniper
    Junos OS EX Series PHP 
    External Variable Modification

    Juniper 
    Junos OS EX Series and SRX Series PHP 
    External Variable Modification

    Juniper 
    Junos OS SRX Series
    Missing Authentication for Critical Function

    Juniper 
    Junos OS EX Series 
    Missing Authentication for Critical Function
     
    Apple
    iOS, iPadOS, and macOS ImageIO
    Buffer Overflow

    Apple
    Apple iOS, iPadOS, and watchOS Wallet 
    Code Execution

    GitLab 
    Community and Enterprise Editions 
    RCE

    Ivanti
    Pulse Connect Secure 
    Arbitrary File Read

    Unitronics 
    Vision PLC and HMI
    Insecure Default Password










    Atlassian 
    Confluence Server and Data Center 
    Object-Graph Navigation Language (OGNL) Injection

    Dahua
    Various products
    Authentication Bypass

    Dahua
    Various products
    Authentication Bypass

    Sophos 
    Firewall
    Code Injection

    Atlassian
    Confluence Server and Data Center 
    RCE

    Microsoft
    Exchange Server
    Server-Side Request Forgery

    RARLAB
    WinRAR
    Code Execution














Mitigations



Vendors and Developers


The authoring agencies recommend vendors and developers take the following steps to help ensure their products are secure by design and default:



  • Identify repeatedly exploited classes of vulnerability.

    • Perform an analysis of both CVEs and and implement secure by design practices into each stage of the SDLC; in particular, aim to perform the following SSDF recommendations:

      • Prioritize the use of memory safe languages wherever possible [].

      • Set up secure software development team practices—this includes conducting peer code reviews, working to a common organization secure coding standard, and maintaining awareness of language-specific security concerns [ to verify and resolve security vulnerabilities disclosed by people who may be internal or external to the organization [].



    • Configure production-ready products to have the most secure settings by default and provide guidance on the risks of changing each setting [.


      End-User Organizations


      The authoring agencies recommend end-user organizations implement the mitigations below to improve their cybersecurity posture based on threat actors’ activity. These mitigations align with the cross-sector Cybersecurity Performance Goals (CPGs) developed by CISA and the National Institute of Standards and Technology (NIST). The CPGs provide a minimum set of practices and protections that CISA and NIST recommend all organizations implement. CISA and NIST based the CPGs on existing cybersecurity frameworks and guidance to protect against the most common and impactful threats, tactics, techniques, and procedures. Visit CISA’s ].


      • Prioritize patching

        • Organizations that are unable to perform rapid scanning and patching of internet-facing systems should consider moving these services to mature, reputable cloud service providers (CSPs) or other managed service providers (MSPs).

        • Reputable MSPs can patch applications (such as webmail, file storage, file sharing, chat, and other employee collaboration tools) for their customers.
          Note: MSPs and CSPs can expand their customer’s attack surface and may introduce unanticipated risks, so organizations should proactively collaborate with their MSPs and CSPs to jointly reduce risk [.

        • CISA Insights’ .





    • Document secure baseline configurations for all IT/OT components, including cloud infrastructure.

      • Monitor, examine, and document any deviations from the initial secure baseline [].



    • Maintain an updated cybersecurity incident response plan that is tested at least annually and updated within a risk informed time frame to ensure its effectiveness [].

    • Enforce MFA on all VPN connections.

      • If MFA is unavailable, require employees engaging in remote work to use strong passwords [, , , ].

        • Ensure software service accounts only provide necessary permissions (least privilege) to perform intended functions (using non-administrative privileges where feasible).
          Note: See CISA’s for more information on authentication system hardening.




      Protective Controls and Architecture



      • Properly configure and secure internet-facing network devices, disable unused or unnecessary network ports and protocols, encrypt network traffic, and disable unused network services and devices [, , and the Department of Defense’s ].

      • Use security tools, such as endpoint detection and response (EDR) and security information and event management (SIEM) tools.

      • Consider using an information technology asset management (ITAM) solution to ensure EDR, SIEM, vulnerability scanners, and other similar tools are reporting the same number of assets [].

      • Use web application firewalls to monitor and filter web traffic.

      • These tools are commercially available via hardware, software, and cloud-based solutions, and may detect and mitigate exploitation attempts where a cyber actor sends a malicious web request to an unpatched device [].

      • Implement an administrative policy and/or automated process configured to monitor unwanted hardware, software, or programs against an allowlist with specified, approved versions [].

      • Ensure contracts require vendors and/or third-party service providers to:

      • Provide notification of security incidents and vulnerabilities within a risk informed time frame [, ].

      • Ask your software providers to discuss their secure by design program, provide links to information about how they are working to remove classes of vulnerabilities, and to set secure default settings.


      Resources



      • For information on the top vulnerabilities routinely exploited in 2016–2019, 2020, 2021, and 2022:

        • Joint CSA .

        • Joint CSA .



      • See the Appendix for additional partner resources on the vulnerabilities mentioned in this advisory.

      • See ACSC’s for additional considerations and advice.


      References



      • or the FBI’s CyWatch at (855) 292-3937 or or call 1300 292 371 (1300 CYBER 1) to report cybersecurity incidents and access alerts and advisories.


        Canadian organizations: Report incidents by emailing CCCS at (monitored 24 hours).


        Disclaimer


        The information in this report is being provided “as is” for informational purposes only. CISA, FBI, NSA, ACSC, CCCS, NCSC-NZ, CERT NZ, and NCSC-UK do not endorse any commercial product or service, including any subjects of analysis. Any reference to specific commercial products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring.


        Version History


        November 12, 2024: Initial version.



Appendix: Patch Information and Additional Resources for Top Exploited Vulnerabilities

















































































































































































CVE Vendor Affected Products and Versions Patch Information Resources




Fortinet

FortiOS-6K7K versions:


7.0.10, 7.0.5, 6.4.12


6.4.10, 6.4.8, 6.4.6, 6.4.2


6.2.9 through 6.2.13


6.2.6 through 6.2.7


6.2.4


6.0.12 through 6.0.16


6.0.10


Progress

MOVEit Transfer:


2023.0.0 (15.0)


2022.1.x (14.1)


2022.0.x (14.0)


2021.1.x (13.1)


2021.0.x (13.0)


2020.1.x (12.1)


2020.0.x (12.0) or older MOVEit Cloud



(Log4Shell)


Apache

Log4j, all versions from 2.0-beta9 to 2.14.1


For other affected vendors and products, see CISA's GitHub repository.



Apache Log4j Security Vulnerabilities


For additional information, see joint advisory:

 
) PaperCut

PaperCut MF or NG version 8.0 or later (excluding patched versions) on all OS platforms. This includes:


version 8.0.0 to 19.2.7 (inclusive)


version 20.0.0 to 20.1.6 (inclusive)


version 21.0.0 to 21.2.10 (inclusive)


version 22.0.0 to 22.0.8 (inclusive)


ownCloud graphapi Cisco Cisco IOS XE Software with web UI feature enabled
Atlassian All versions of Confluence Data Cetner and Confluence Server  
 

ACSC Alert:


Fortra GoAnywhere versions 2.3 through 7.1.2
 
 
 
  Ivanti All supported versions of Endpoint Manager Mobile (EPMM), including 11.10, 11.9 and 11.8 CVE-2023-35081 -
 
 
 
 



Apple Versions prior to:
watchOS 9.6.2, iOS 16.6.1 and iPadOS 16.6.1


 
 
Unitronics

VisiLogic versions before


9.9.00


Cisco Simple Network Management Protocol subsystem of Cisco IOS 12.0 through 12.4 and 15.0 through 15.6 and IOS XE 2.2 through 3.17 Red Hat

Red Hat Enterprise Linux 6


Red Hat Enterprise Linux 7


Red Hat Enterprise Linux 8


Red Hat Virtualization 4


Any Red Hat product supported on Red Hat Enterprise Linux (including RHEL CoreOS) is also potentially impacted.


Dahua Various products Dahua Various products Sophos Sophos Firewall v19.0 MR1 (19.0.1) and older
Microsoft Microsoft Exchange servers RARLAB WinRAR Versions prior to 6.23 Beta 1 Progress Telerik Telerik.Web.UI.dll versions:

 
Iranian Government-Sponsored APT Cyber Actors Exploiting Microsoft Exchange and Fortinet Vulnerabilities in Furtherance of Malicious Activities