CISA’s Known Exploited Vulnerabilities (KEV) catalog saw a record 244 new entries in 2025, marking a 28% increase from the previous year and reflecting a significant escalation in actively exploited vulnerabilities. The majority of these additions targeted network devices, operating systems, and browsers, with Microsoft, Cisco, and Fortinet among the most affected vendors. The analysis highlights a shift in vulnerability management priorities, emphasizing the need to focus on real-world exploitation patterns rather than traditional CVSS scores, as attackers increasingly target network edge devices and critical infrastructure.
In parallel, 2025 was characterized by a dramatic rise in network device exploitation, including high-profile incidents involving Cisco and F5, and the disclosure of three new network edge device vulnerabilities just before the year’s end. Notably, critical authentication bypass flaws (CVE-2025-59718 & CVE-2025-59719) in Fortinet’s FortiCloud SSO were identified, allowing unauthenticated attackers to gain access if the feature is enabled. These developments underscore the urgency for organizations to rapidly apply vendor patches and reassess vulnerability prioritization strategies, as attackers increasingly exploit both newly disclosed and older, medium-risk vulnerabilities in network infrastructure.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
By the end of 2025, CISA had added 244 vulnerabilities to the KEV catalog, a 28% increase over 2024. Reporting highlighted a shift toward exploitation of network appliances and browsers, with vendors such as Microsoft, Cisco, Fortinet, and Google Chromium heavily represented.
In 2025, CISA added newly disclosed and actively exploited vulnerabilities affecting Fortinet FortiCloud SSO, HPE OneView, and SonicWall SMA1000 to its Known Exploited Vulnerabilities catalog. The listed flaws included authentication bypass, privilege escalation, and remote code execution issues.
During 2025, CISA responded to active exploitation of major network-device vulnerabilities by issuing emergency directives, reflecting the growing operational risk posed by edge appliances.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.