A CISA review of fiscal years 2024 and 2025 reveals that most compromises stem from opportunistic criminals exploiting known, exposed weaknesses rather than nation-state zero-day attacks. Approximately 41.5 percent of entries in the Known Exploited Vulnerabilities catalog correspond to weakness classes that have consistently appeared on the CWE Top 25 since 2019. This data suggests financial institutions should prioritize patching established vulnerabilities over focusing exclusively on advanced threats.
Relevant URL: https://www.helpnetsecurity.com/2026/09/01/cisa-on-eliminating-recurring-security-weaknesses/