LackyVis - stock.adobe.com

* Share this item with your network:

By

* [Alex Scroxton,](https://www.techtarget.com/contributor/Alex-Scroxton)
  Security Editor

Published: 06 Aug 2024 17:05

Over the first seven-and-a-half months of 2024, the number of newly-disclosed [common vulnerabilities and exposures](https://www.techtarget.com/searchsecurity/definition/Common-Vulnerabilities-and-Exposures-CVE) (CVEs) soared [30% year-on-year](https://www.computerweekly.com/news/366570913/CVE-volumes-set-to-increase-25-this-year) from 17,114 to 22,254, according to data published by Qualys researchers.

However, out of this huge number of flaws, barely a hundredth - 204 or 0.9% - were weaponised by threat actors, said Qualys, the majority of whom exploit public-facing applications or remote services, which are useful to obtain initial access and conduct lateral movement.

Read at face value this statistic may feel like good news, but it offers only meagre solace for cyber professionals, Qualys said, for these vulnerabilities still present a significant threat and necessitate ever-more focused defensive measures.

“This very small fraction of vulnerabilities accounts for the most severe threats. This subset represents the highest risk, characterised by weaponised exploits, active exploitation through ransomware, use by threat actors, malware, or confirmed wild exploitation instances,” [said Qualys’ Threat Research Unit (TRU) product manager, Saeed Abbasi](https://blog.qualys.com/vulnerabilities-threat-research/2024/08/06/2024-midyear-threat-landscape-review).

“To effectively mitigate such threats, it’s crucial to prioritise actively exploited vulnerabilities, leverage threat intelligence, and regularly schedule scans to detect new vulnerabilities. A vulnerability management tool that integrates threat intelligence could be pivotal for an enterprise."

According to Qualys’ data collection and analysis exercise, the most exploited vulnerabilities of 2024 to date are as follows:

1. CVE-2024-21887, a command injection flaw in Ivanti Connect and Policy Secure Web;
2. CVE-2023-46805, a remote authentication bypass flaw in Ivanti Connect and Policy Secure Web;
3. CVE-2024-21412, a security feature bypass flaw in Microsoft Windows;
4. CVE-2024-21893, a elevation of privilege flaw in Ivanti Connect and Policy Secure Web;
5. CVE-2024-3400, a command injection flaw in Palo Alto Networks PAN-OS;
6. CVE-2024-1709, an authentication bypass flaw in ConnectWise ScreenConnect;
7. CVE-2024-20399, a command line interface command injection flaw in Cisco NX-OS Software;
8. CVE-2024-23897, a remote code execution flaw in Jenkins Core;
9. CVE-2024-21762, an out-of-bound write flaw in Fortinet FortiOS;
10. CVE-2023-38112, a MSHTLM platform spoofing flaw in Microsoft Windows.

With the exception of the Jenkins Core vulnerability, all of the Qualys top 10 also appear on the US Cybersecurity and Infrastructure Security Agency (CISA) known exploited vulnerabilities (KEV) catalogue mandating patching across US government bodies.

Many of these vulnerabilities, [notably those in Ivanti’s product set](https://www.computerweekly.com/feature/Ivanti-vulnerabilities-explained-Everything-you-need-to-know) and [ConnectWise ScreenConnect](https://www.computerweekly.com/news/366571077/Cyber-experts-alarmed-by-trivial-ConnectWise-vulns), have already been at the centre of some of the most impactful cyber security incidents of the year so far. The final vulnerability on the list, in the Windows MSHTML Platform, was only disclosed a few weeks ago [in the July Patch Tuesday update](https://www.computerweekly.com/news/366592779/Hyper-V-zero-day-stands-out-on-a-busy-Patch-Tuesday), and although [it has likely been exploited since 2023](https://www.techtarget.com/searchsecurity/news/366593234/Check-Point-sheds-light-on-Windows-MSHTML-zero-day-flaw), its inclusion on Qualys’ top 10 list serves as a warning to admins of the speed with which threat actors pick up on publicised vulnerabilities.

## Old vulnerabilities prove their worth

The overall upward trend in CVE volumes underscores a “persistent and substantial escalation” in vulnerability discovery, explained Abbasi.

“The increase in CVEs reflects rising software complexity and the broader use of technology, necessitating advanced and dynamic vulnerability management strategies to mitigate evolving cyber security threats,” he said.

However, the Qualys TRU’s analysis has also indicated an increase in the weaponisation of old CVEs this year. While older bugs often resurface and exploits are developed well after disclosure, there has been a 10% increase in this sort of activity so far this year. Abbasi said this was a “stark reminder” that security was not just about staying ahead of threat actors, but also not falling behind them.

Many of the older weaponised vulnerabilities in circulation have been trending on the dark web for months, one prominent example being CVE-2023-43208 in NextGen Mirth Connect Java XStream, heavily used by the health sector. And just this week, CISA added [a six year-old remote code execution bug in Microsoft COM](https://www.computerweekly.com/news/366599914/Chinese-cyber-attack-sparks-alert-over-six-year-old-MS-vuln) to the KEV catalogue, after Cisco Talos researchers found it being exploited by a Chinese government APT in an attack chain used against a Taiwanese victim.

“This resurgence of previously identified vulnerabilities, which mainly impact remote services and public-facing applications, highlights a significant oversight in updating and enforcing cyber security protocols. This re-emergence emphasises the need to shift from a purely reactive security posture to a more proactive, predictive, and preventative approach,” advised Abbasi.

### Read more about patch management

* Some risks, like security vulnerabilities and system downtime, are obvious, others not so much. Good patch management also requires [weighing the possible risks of patching](https://www.techtarget.com/searchenterprisedesktop/tip/The-risks-of-failed-patch-management).
* Compare the features of eight prominent patch management tools for Microsoft operating systems and third-party applications [to find the right option for your organisation](https://www.techtarget.com/searchwindowsserver/feature/5-WSUS-alternatives-for-patch-management).
* While patching desktops has some universal aspects across systems, there are specific Linux best practices that Linux administrators need to know. [Here are eight important ones](https://www.techtarget.com/searchenterprisedesktop/tip/3-crucial-Linux-patch-management-best-practices-for-IT).

#### Read more on Application security and coding requirements

* [##### Eight critical RCE flaws make Microsoft’s latest Patch Tuesday list

  By: Alex Scroxton](https://www.computerweekly.com/news/366629273/Eight-critical-RCE-flaws-make-Microsofts-latest-Patch-Tuesday-list)
* [##### July Patch Tuesday brings over 130 new flaws to address

  By: Alex Scroxton](https://www.computerweekly.com/news/366627196/July-Patch-Tuesday-brings-over-130-new-flaws-to-address)
* [##### Biggest Patch Tuesday in years sees Microsoft address 159 vulnerabilities

  By: Alex Scroxton](https://www.computerweekly.com/news/366617968/Biggest-Patch-Tuesday-in-years-sees-MS-address-159-vulns)
* [##### Ivanti zero-day vulnerabilities exploited in chained attack

  By: Alexander Culafi](https://www.techtarget.com/searchsecurity/news/366613041/Ivanti-zero-day-vulnerabilities-exploited-in-chained-attack)

Latest News

* [Interview: Ankur Anand, group CIO, Nash Squared](https://www.computerweekly.com/news/366639074/Interview-Ankur-Anand-group-CIO-Nash-Squared)
* [Telefónica activates commercial Edge services in Spain](https://www.computerweekly.com/news/366639110/Telefonica-activates-commercial-Edge-services-in-Spain)
* [UK AI alignment project gets OpenAI and Microsoft boost](https://www.computerweekly.com/news/366639303/UK-AI-alignment-project-gets-OpenAI-and-Microsoft-boost)
* [View All News](https://www.computerweekly.com/news)

Download Computer Weekly

* In The Current Issue:
  + How charities are using customer applications to boost support
  + Post Office offered bailout to cover £104.4m IR35 tax bill linked to Horizon IT scandal
  + Interview: Mariano Albera, CTO, Checkout.com[Download Current Issue](https://www.computerweekly.com/ezine/Computer-Weekly/Charities-turn-to-tech-for-greater-impact)

Latest Blog Posts

* [GreenOps - BlackLine: Why GreenOps needs finance-grade control to deliver value](https://www.computerweekly.com/blog/CW-Developer-Network/GreenOps-BlackLine-Why-GreenOps-needs-finance-grade-control-to-deliver-value)
  – CW Developer Network
* [What to expect from ABBYY Ascend 2026](https://www.computerweekly.com/blog/CW-Developer-Network/What-to-expect-from-ABBYY-Ascend-2026)
  – CW Developer Network
* [View All Blogs](https://www.computerweekly.com/blogs)

Related Content

* [Critical OpenSSH vulnerability could affect millions ...](https://www.techtarget.com/searchsecurity/news/366592376/Critical-OpenSSH-vulnerability-could-affect-millions-of-servers)
  – Search Security
* [Windows Kerberos, Hyper-V vulns among January Patch ...](https://www.computerweekly.com/news/366565740/Windows-Kerberos-Hyper-V-vulns-among-January-Patch-Tuesday-bugs)
  – ComputerWeekly.com
* [Eight critical RCE flaws make Microsoft’s latest ...](https://www.computerweekly.com/news/366629273/Eight-critical-RCE-flaws-make-Microsofts-latest-Patch-Tuesday-list)
  – ComputerWeekly.com