Exploited CVEs of 2024: Lessons for Vendors and Defenders

Patrick Gity (Security Researcher · Vone)

CVE/FIRST VulnCon 2025 · Main Stage

Overview

Patrick Gity, a security researcher at Vone, delivered a compelling talk at VulnCon, shedding light on the landscape of exploited vulnerabilities in 2024. His presentation, titled "Exploited CVEs of 2024: Lessons for Vendors and Defenders," provided a data-driven analysis of vulnerabilities actively leveraged by threat actors in the wild. Gity's work, rooted in Vone's extensive data collection and analysis, aims to enhance transparency around exploitation evidence, offering critical insights for both product vendors and cybersecurity defenders.

Watch on YouTube

Visual summary for Exploited CVEs of 2024: Lessons for Vendors and Defenders by Patrick Gity
Visual summary for Exploited CVEs of 2024: Lessons for Vendors and Defenders by Patrick Gity

Key moments

  1. 0:00 Introduction: Exploited CVEs of 2024
  2. 2:00 Understanding the threat matrix and exploited vulnerabilities
  3. 4:00 Defining known exploited vulnerabilities and data sources
  4. 6:00 Key statistics for 2024 exploited vulnerabilities
  5. 8:00 Acknowledging biases in the data collection process

Exploited CVEs of 2024: Lessons for Vendors and Defenders

Speakers: Patrick Gity, Security Researcher, Vone

Conference: VulnCon

YouTube: https://www.youtube.com/watch?v=gcATPV7d23I

Overview

Patrick Gity, a security researcher at Vone, delivered a compelling talk at VulnCon, shedding light on the landscape of exploited vulnerabilities in 2024. His presentation, titled "Exploited CVEs of 2024: Lessons for Vendors and Defenders," provided a data-driven analysis of vulnerabilities actively leveraged by threat actors in the wild. Gity's work, rooted in Vone's extensive data collection and analysis, aims to enhance transparency around exploitation evidence, offering critical insights for both product vendors and cybersecurity defenders.

The core of Gity's discussion revolved around a critical distinction: not all vulnerabilities are created equal, especially when considering the urgency of patching. By focusing exclusively on known exploited vulnerabilities (KEVs), Gity articulated a framework for prioritizing defensive actions and understanding attacker methodologies. The talk is particularly relevant in an era where the sheer volume of reported CVEs can overwhelm organizations, making targeted, intelligence-led prioritization indispensable for effective risk management.

This talk matters immensely because it shifts the focus from theoretical risk to actual threat. Gity's research underscores the immediate and tangible dangers posed by vulnerabilities that are actively being exploited, providing a clear call to action for defenders to allocate resources where they are most needed. For vendors, it offers a stark reminder of the types of vulnerabilities that attackers actively seek and exploit, informing more robust security development and disclosure practices.

Background

▶ Watch: Introduction: Exploited CVEs of 2024 (0:00)

The landscape of cybersecurity is perpetually defined by a race between attackers and defenders. Central to this dynamic are vulnerabilities, flaws in software or hardware that can be exploited to compromise systems. While thousands of vulnerabilities are discovered and assigned CVE (Common Vulnerabilities and Exposures) identifiers annually, only a fraction are ever actively exploited in real-world attacks. Understanding this critical subset—known exploited vulnerabilities (KEVs)—is paramount for effective cybersecurity.

Gity introduced a threat matrix that categorizes vulnerabilities based on their exploitability and observed activity. At the "tip of the spear" are KEVs, which can be further refined by attribution (e.g., ransomware or botnet campaigns) or simply as known exploitation without specific actor ties. Below this tier lie weaponized vulnerabilities, often found in exploit frameworks like Metasploit or commercial tools, indicating a higher likelihood of exploitation. Further down are vulnerabilities with publicly available Proof of Concept (PoC) code, which can quickly evolve into weaponized exploits. The vast majority of reported CVEs, however, lack any of these indicators, making them a lower priority for immediate action compared to KEVs.

A key aspect of Gity's background discussion was the methodology for identifying KEVs. Unlike some definitions, Vone's research is inclusive of, but not limited to, vulnerabilities listed in CISA's Known Exploited Vulnerabilities (KEV) Catalog. Gity highlighted that while CISA's catalog is an excellent resource, it represents a federal scope and does not capture the full breadth of observed exploitation globally. Vone's approach involves aggregating evidence from a multitude of trusted public sources, ensuring a comprehensive view of emerging threats. This multi-source aggregation is crucial because exploitation evidence often appears in various places—vendor advisories, security researcher blogs, threat intelligence reports, and even social media—before being formally recognized by official bodies. The problem exists because defenders are often overwhelmed by the volume of reported vulnerabilities, making it difficult to discern which ones pose an immediate, active threat. Without a clear, data-driven prioritization mechanism, organizations risk expending resources on theoretical risks while active threats go unaddressed.

Key Findings

▶ Watch: Understanding the threat matrix and exploited vulnerabilities (2:00)

Gity's research for 2024 revealed several critical findings regarding exploited vulnerabilities, offering a clear picture for vendors and defenders.

Firstly, the volume of known exploited vulnerabilities is substantial and continuously growing. As of the talk, Vone had identified over 800 vulnerabilities with public exploitation evidence disclosed for the first time in 2024. This number is dynamic, with new evidence continually emerging and sometimes predating initial reports. This figure is significantly higher than what is typically captured by narrower scopes, such as the CISA KEV catalog, underscoring the importance of a broad intelligence collection strategy. Gity noted that there are over 2,000 known exploited reference citations across more than 100 unique sources, highlighting the distributed nature of exploitation evidence.

A significant portion of these KEVs were linked to ransomware campaigns, with 53 vulnerabilities specifically associated with known ransomware activity. While this represents a smaller percentage of the overall KEV count, these vulnerabilities often pose the highest immediate risk to enterprise organizations due to the severe impact of ransomware.

Gity also presented an analysis of the sources of exploitation evidence. While major vendors like Microsoft (through MSRC advisories), Google (Project Zero), and Apple contribute to disclosures, the vast majority of exploitation evidence originates from security researchers and threat intelligence firms. He cited examples like Shadow Server honeypots, GitHub exploits, and reports from firms like Rapid7, SANS, Fortinet, Tenable, and Qualys (mentioned in Q&A). This emphasizes the critical role of the broader security community in identifying and publicizing active threats. Gity strongly encouraged all CNAs (CVE Numbering Authorities) and vendors to explicitly disclose exploitation evidence in their advisories or CVE records to aid defenders.

When categorizing the types of technologies most frequently exploited, Gity initially highlighted Content Management Systems (CMS), particularly WordPress plugins, as a pervasive and high-target area. He noted that Vone worked to secure CVEs for approximately 62 exploited WordPress plugins. However, when abstracting away CMS vulnerabilities to focus on enterprise-specific threats, a clear pattern emerged:

  • Network Edge Devices: These devices, often internet-facing, are primary targets for initial access.
  • Operating Systems: Continuous patching and robust mitigating controls like EDR (Endpoint Detection and Response) are essential.
  • Open Source Software: A significant target, requiring application developers to be vigilant.
  • Virtualization Technologies: Critical infrastructure components that, if compromised, can have widespread impact.
  • Backup and Email Systems: Frequently targeted for data exfiltration or phishing campaigns.

Finally, Gity presented a pointed critique of traditional vulnerability scoring systems like CVSS (Common Vulnerability Scoring System) and even the newer EPSS (Exploit Prediction Scoring System), particularly in the context of emerging threats. He demonstrated that the distribution of severity scores (Critical, High, Medium) for KEVs using CVSS Base Score (CVSSB) looks remarkably similar to the distribution for all vulnerabilities, making it difficult for defenders to prioritize. Even applying CVSS Temporal Score (CVSSBT), which accounts for exploit availability, only marginally moves the needle for top-scoring vulnerabilities. Gity showed that EPSS V3 often assigned low scores to vulnerabilities that were already actively exploited, indicating a delay in its predictive capability. While EPSS V4, with retraining, showed improvement for past KEVs, its real-time effectiveness for new emerging threats remains to be seen. This highlighted a significant gap: current scoring systems often fail to provide clear, immediate signals for vulnerabilities under active exploitation.

Technical Deep Dive

▶ Watch: Defining known exploited vulnerabilities and data sources (4:00)

Gity's presentation offered a deep dive into the technical methodology Vone employs to identify and track known exploited vulnerabilities, as well as the classifications used to make this data actionable for defenders.

Vone's process for defining and identifying known exploited vulnerabilities (KEVs) is rigorous and multi-faceted. It begins with the principle that any vulnerability publicly reported as exploited in the wild is included. The system prioritizes trusted sources, avoiding unverified automation where text-based analysis can lead to false positives. Key reliable automated ingestion sources include:

  • CISA KEV Catalog: A foundational source for federally mandated patching.
  • Project Zero: Google's elite security research team, known for high-quality disclosures.
  • Shadow Server: A non-profit organization that operates honeypots and monitors botnets, often providing early indicators of exploitation.
  • Microsoft MSRC: Microsoft's Security Response Center, which frequently discloses exploitation evidence in its advisories, particularly around Patch Tuesday.

Beyond these automated feeds, Vone also aggregates information from hundreds of other sources, including security researcher blogs, threat intelligence reports, and direct tips from the community via channels like LinkedIn. Gity emphasized the importance of public disclosure of exploitation evidence, as it benefits the entire defense community by providing early visibility into emerging threats. All evidence collected is publicly verifiable, ensuring transparency.

A crucial aspect of Vone's work, given its status as a CNA (CVE Numbering Authority), is the coordination of CVE assignments for exploited vulnerabilities that might initially lack one. Gity highlighted instances where Vone worked with other CNAs and intelligence firms to ensure timely CVE assignment and coordinated disclosure for actively exploited flaws, such as the 62 WordPress plugins he mentioned. This proactive approach helps standardize the identification and tracking of emerging threats.

Gity's categorization of KEVs into distinct technology groups is a practical application of his research for defenders. He explained that these categories are designed to align with common enterprise organizational structures and IT asset types, facilitating targeted defensive strategies.

  • Network Edge Devices: These include firewalls, VPNs, routers, and other perimeter security devices. They are critical because they often represent the initial point of compromise for threat actors seeking to gain initial access to an internal network. Gity stressed the importance of ensuring these devices are not end-of-life (EOL), are patched quickly, and have robust mitigating controls.
  • Operating Systems: Encompassing Windows, Linux, macOS, and mobile OS, these form the backbone of most IT environments. Regular patching, often guided by events like Patch Tuesday, and deployment of EDR (Endpoint Detection and Response) solutions are key defensive measures.
  • Open Source Software: This category is particularly relevant for application developers. Gity noted that the technologies within this segment that experience exploitation should prompt organizations to establish specific processes for managing emerging threats in their open-source dependencies.
  • Content Management Systems (CMS): While a broad category, WordPress plugins were singled out due to their high exploitation rate. Gity advised strong compensating controls, regular plugin updates, and pruning of unused plugins. He also linked CMS exploitation to broader campaigns, such as Blackbasta ransomware, which leveraged vulnerable WordPress email services for phishing.
  • Virtualization Technologies: Hypervisors and virtual machine management platforms are high-value targets. Exploiting a vulnerability in these systems can grant an attacker control over multiple virtualized environments.
  • Backup and Email Systems: These are critical for business continuity and communication. Their exploitation can lead to data loss, exfiltration, or become a vector for further attacks (e.g., using compromised email for phishing).

Gity's critique of vulnerability scoring systems also involved a technical examination. He showed that CVSS Base Score (CVSSB), while providing a technical severity, fails to differentiate KEVs from unexploited vulnerabilities effectively. The distribution of critical, high, and medium scores for KEVs mirrored that of all vulnerabilities, rendering it unhelpful for prioritization. Even the more dynamic CVSS Temporal Score (CVSSBT), which incorporates exploit availability, only offers marginal improvement. Gity demonstrated with a real-world example of a Microsoft Windows vulnerability (CVE not explicitly stated but described as a June 2023 vulnerability that became KEV) how its CVSSBT score was 7.8, while its EPSS V3 score was low, only to be rescored higher with EPSS V4 after the fact. This retrospective improvement in EPSS V4 for last year's KEVs, while validating the evidence, highlights the challenge of using predictive scores for truly emerging threats in real-time. Gity's technical argument is that relying solely on these scores for prioritization of KEVs is "very dangerous" due to their inherent limitations in signaling immediate, active threats.

Demo / Proof of Concept

▶ Watch: Key statistics for 2024 exploited vulnerabilities (6:00)

The talk focused on data analysis, trends, and strategic insights rather than a live demonstration. Patrick Gity did not present a demo or proof of concept code during his presentation. Instead, he referenced the availability of Vone's free service and API access, encouraging attendees to download and validate the research data themselves.

Defensive Implications

▶ Watch: Acknowledging biases in the data collection process (8:00)

Gity's comprehensive analysis of exploited CVEs provides crucial, actionable intelligence for cybersecurity defenders, emphasizing a shift from reactive patching to proactive, intelligence-driven risk management.

1. Prioritize Based on Exploitation Evidence: The foremost implication is to move beyond generic vulnerability scores (like CVSSB) as the sole basis for prioritization. Defenders must "act on available exploitation evidence, weaponization, and other exploit evidence with a sense of urgency." This means actively monitoring sources like the CISA KEV catalog, Project Zero, Shadow Server, and security researcher disclosures, not just official vendor advisories. If a vulnerability is known to be exploited in the wild, it demands immediate attention, regardless of its raw CVSS score.

2. Strategic Capacity Planning: Given that new disclosures of exploitation happen almost daily, defenders need to factor this continuous influx into their capacity planning. Gity showed a graph indicating daily exploitation disclosures, highlighting that organizations should have dedicated resources or processes to quickly assess impact and patch status for these emerging threats. This "rapid response" capability is critical for internet-facing systems and user-facing devices, which are frequently targeted.

3. Focus on High-Risk Technology Categories: Defenders should establish quick patch processes and robust mitigating controls for the technology categories identified as high-target areas for exploitation:

  • Network Edge Devices: These "initial access devices" are prime targets. Ensure they are patched immediately, not end-of-life, and have strong compensating controls.
  • Operating Systems: Maintain rigorous patch management cycles, leveraging events like Patch Tuesday, and deploy advanced EDR solutions.
  • Open Source Software: Application development teams must be aware of exploited open-source components and implement processes for handling emerging threats within their software supply chain.
  • Content Management Systems (CMS): For pervasive technologies like WordPress, ensure plugins are updated, unused plugins are pruned, and strong compensating controls are in place. Be aware of how these can be leveraged in broader campaigns (e.g., for phishing).
  • Virtualization, Backup, and Email Systems: These critical infrastructure components are high-value targets and require continuous vigilance.

4. Exercise Caution with Scoring Systems: Defenders must understand the limitations of vulnerability scoring systems like CVSS and EPSS, especially for emerging threats. Gity explicitly stated that relying "solely on that is very dangerous." While these systems have their place, they often lag behind real-world exploitation or fail to provide a clear signal for immediate action. Organizations should avoid becoming "overly independent" on these scores without human analysis and monitoring. Instead, integrate these scores as components within broader risk-based prioritization frameworks like SSVC (Stakeholder-Specific Vulnerability Categorization) or methods published by researchers like Chris Madden, which allow for the incorporation of real-world exploitation evidence.

5. Address Vulnerability Debt and Best Practices: Beyond emerging threats, Gity touched upon the broader issue of vulnerability debt. Defenders should engage in root cause analysis for recurring issues, continuously improve patch management processes, and implement best practices such as pruning and removing end-of-life technologies. Implementing the right mitigating controls is a continuous effort to reduce the overall attack surface and resilience against exploitation.

In essence, Gity's talk is a call for defenders to embrace an intelligence-led approach, prioritizing resources based on concrete evidence of active exploitation, rather than theoretical severity scores alone.

Key Takeaways

  • Exploitation Evidence is Paramount: Prioritize patching and defensive actions based on known exploitation evidence (KEVs) over generic vulnerability scores like CVSS Base Score.
  • KEV Volume is Significant: Over 800 vulnerabilities had public exploitation evidence disclosed for the first time in 2024, with 53 linked to ransomware, far exceeding narrower catalogs like CISA KEV.
  • Diverse Sources of Intel: Actively monitor a wide range of sources for exploitation evidence, including security researchers, threat intelligence firms (Shadow Server, Project Zero), and vendor disclosures (Microsoft MSRC), as they often provide earlier indicators.
  • Targeted Technology Focus: Implement rapid response and robust patch management for high-target categories such as network edge devices, operating systems, open source software, and content management systems.
  • Scoring System Limitations: Use vulnerability scoring systems (CVSS, EPSS) with extreme caution for emerging threats, as they often lag or fail to provide clear prioritization signals for actively exploited vulnerabilities.
  • Integrated Risk Prioritization: Leverage frameworks like SSVC and risk-based prioritization methodologies that combine various signals, including exploitation evidence and weaponization, for a more effective defense strategy.

About the Speaker(s)

Patrick Gity is a Security Researcher at Vone, a CNA (CVE Numbering Authority). His work primarily focuses on initial access and exploitation, making him a key figure in understanding how threat actors compromise systems. Gity collaborates closely with Vone's research team and various intelligence organizations, assisting with CVE assignment and coordinated disclosure. He is dedicated to transparency in sharing data and evidence related to exploitation, aiming to provide valuable insights for both vendors and defenders in the cybersecurity community.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Gity delivers a competent, data-driven threat intelligence briefing on 2024's exploited CVE landscape. The core thesis — that exploitation evidence should drive prioritization over raw CVSS scores — is correct and important, but it's not new. The talk's value comes from Vone's proprietary aggregation work (800+ KEVs, 100+ sources, 2000+ citations) and the pointed critique of EPSS V3's real-time limitations. It's a solid intel briefing with genuine practitioner utility, but it doesn't fundamentally advance the conversation beyond what CISA KEV + VulnCheck + GreyNoise have been saying for years. The right talk for the right conference; just not one that will be cited in five years.

Heather Calloway (CISO) — SOLID

Patrick Gity delivers competent, data-grounded work on exploitation prioritization — 800+ KEVs in 2024, CVSS and EPSS limitations, technology category targeting — that is genuinely useful for vulnerability management teams. The research is honest about what scoring systems can and cannot do, and the multi-source aggregation methodology is a real contribution to defender intelligence. But the talk stays at the operational tier and never climbs to where the governance and accountability questions live. Who in an organization owns the decision to act on exploitation evidence? What does it mean institutionally when your patch cycle is slower than the exploitation disclosure rate? Those…

→ Top-rated talks at CVE/FIRST VulnCon 2025

All talks from CVE/FIRST VulnCon 2025