---
title: "Successful Vulnerability Management: The Must-Know Vulnerabilities Your Business Needs to Fix"
description: The Cybersecurity and Infrastructure Security Agency (CISA) in the US recently released its annual top routinely exploited vulnerabilities report. It is co-authored by a number of cybersecurity authorities worldwide and aims to summarize the vulnerabilities having the biggest impact on organizations.
image: https://csacyber.com/hubfs/vm1.jpg
---

[Skip to content](https://csacyber.com/blog/successful-vulnerability-management-the-must-know-vulnerabilities-your-business-needs-to-fix#main-content)

[![CSA Cyber - Cyber Security Solutions to Protect your People](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Full%20Logo.png?width=300&height=108&name=CSA%20Cyber%20Logo%20FNL_Full%20Logo.png "CSA Cyber - Cyber Security Solutions to Protect your People")](https://csacyber.com/)

- Services 
    - [Offensive Security Services](https://csacyber.com/offensive-security-services) 
          - [Penetration Testing](https://csacyber.com/penetration-testing)
          - [Red Teaming and attack simulations](https://csacyber.com/offensive-security-services#red-teaming)
          - [Continuous testing](https://csacyber.com/offensive-security-services#continuous-assurance)
          - [Managed offensive security](https://csacyber.com/offensive-security-services#managed-offensive)
    - [Consultancy Services](https://csacyber.com/cyber-consultancy-services) 
          - [Frameworks & assessments](https://csacyber.com/cyber-consultancy-services/frameworks-and-assessments)
          - [Data protection](https://csacyber.com/cyber-consultancy-services#data-protection)
          - [Virtual leadership](https://csacyber.com/cyber-consultancy-services#virtual-leadership)
          - [Technical security consulting](https://csacyber.com/cyber-consultancy-services#technical-consultancy)
          - [Governance, Risk & Compliance (GRC)](https://csacyber.com/cyber-consultancy-services/governance-risk-and-compliance-services)
    - [Extended Managed Security Services](https://csacyber.com/extended-managed-security-services) 
          - [Microsoft Sentinel SIEM](https://csacyber.com/extended-managed-security-services#microsoft-sentinel)
          - [SOC services](https://csacyber.com/extended-managed-security-services#soc-services)
          - [SentinelOne Endpoint Detection & Response (EDR)](https://csacyber.com/extended-managed-security-services#cyber-helpdesk)
    - [Incident Response Services](https://csacyber.com/incident-response-services) 
          - [Emergency Incident Response](https://csacyber.com/urgent/emergency-incident-response)
          - [Incident Response Retainer](https://csacyber.com/incident-response-services)
          - [Cyber Incident Readiness & Response Planning](https://csacyber.com/incident-response-services)
          - [Tabletop Exercises & Live-Range Engagements](https://csacyber.com/incident-response-services)
    - [Specialist Security Services](https://csacyber.com/specialist-services) 
          - [AI Security](https://csacyber.com/cyber-services-for-ai)
          - [Operational Technology (OT)](https://csacyber.com/specialist-services#operational-technology)
          - [Cyber security for Private Equity](https://csacyber.com/specialist-services#mergers-and-acquisitions)
          - [Cyber training and education](https://csacyber.com/specialist-services#training-and-education)
          - [Virtual leadership](https://csacyber.com/specialist-services#leadership)
    - [Cyber Technologies](https://csacyber.com/cyber-technologies) 
          - [SentinelOne Endpoint Detection & Response (EDR)](https://csacyber.com/cyber-technologies#sentinelone)
          - [AppGuard Endpoint & Server Zero Trust Protection](https://csacyber.com/cyber-technologies#appguard)
          - [Qualys Vulnerability Management as a Service (VMaaS)](https://csacyber.com/cyber-technologies#qualys-vmaas)
          - [Lookout Mobile Device Protection](https://csacyber.com/cyber-technologies#lookout)
          - [ThreatER DNS Protection](https://csacyber.com/cyber-technologies#threater-dns)
          - [Cyber Security Awareness & Training platform](https://csacyber.com/cyber-technologies#boxphish)
- [About](https://csacyber.com/about-us) 
    - [Careers](https://csacyber.com/careers)
    - [Certifications](https://csacyber.com/certifications-and-awards)
- [Blog](https://csacyber.com/blog)
- [Support Centre](https://csacyber.com/support)
- Resources 
    - [Case Studies](https://csacyber.com/case-studies)
    - [Downloads & Reports](https://csacyber.com/downloads-and-reports)
    - [Webinars](https://csacyber.com/webinars)
    - [Partners](https://csacyber.com/partners)
    - [Cyber Bundles (IT MSPs)](https://csacyber.com/cyber-bundles)
- [Contact](https://csacyber.com/contact-us)

- Search Search
  
  Search

 September 24, 2022

 4 min read time

# Successful Vulnerability Management: The Must-Know Vulnerabilities Your Business Needs to Fix

![Cyber Security Associates](https://app.hubspot.com/settings/avatar/d41d8cd98f00b204e9800998ecf8427e) [Written by: Cyber Security Associates -](https://csacyber.com/blog/author/cyber-security-associates)

[Consultancy](https://csacyber.com/blog/tag/consultancy) 

![](https://csacyber.com/hubfs/vm1.jpg)

The Cybersecurity and Infrastructure Security Agency (CISA) in the US recently released its annual top routinely exploited vulnerabilities report. It is co-authored by a number of cybersecurity authorities worldwide and aims to summarize the vulnerabilities having the biggest impact on organizations.

### What is a vulnerability?

A vulnerability is essentially a weakness in an IT system that a threat actor can exploit to launch a cyberattack. Understanding what vulnerabilities are out there, and managing them, is an important part of any cybersecurity strategy, but one that can also be hard to keep on top of. Let’s take a closer look at the CISA report and find out what the most exploited vulnerabilities are and what you can do to steer your security program in the right direction, with or without the help of IT risk management software.

### Top three most exploited vulnerabilities

**1. Log4Shell:** This vulnerability is found in a popular java application that enables attackers to take control of a victim’s device. Despite how infamous it is, over 68,000 servers are still publicly exposed, with appropriate patching not being completed. Read about our Log4Shell pentest for more information.

**2. ProxyLogon:** This allows cybercriminals to access private information stored in files and mailboxes on Microsoft Exchange as well as any confidential login details saved on the hard drive.

**3. ProxyShell:** Also affecting Microsoft Exchange email servers, but in this case, the vulnerability allows an attacker to execute arbitrary code that could give a cybercriminal a higher set of privileges, gaining them access to sensitive data.

### How are these vulnerabilities still able to make an impact?

It’s important to note that these top three vulnerabilities, and indeed the majority of the list identified by CISA, are not new. Fixes exist for them, so why do they remain majorly exploited? Well, there can be a few different reasons a company might not patch immediately.

We often see huge timelines between patches being released and installed when businesses have poor inventory and asset management. As a result, companies might not even be aware that a device or system exists in their infrastructure with that vulnerability.

In other cases, there could be mission-critical machinery that can only run on legacy software. Take the healthcare sector, for example. Hospitals may have MRI scanners that can only run on Windows XP. This means patching is not always possible, so it’s important to reduce the time that a device like this spends networked.

In addition to targeting vulnerabilities in email servers, the CISA report also mentions how cybercriminals target other internet-facing systems, such as virtual private networks (VPNs). Since the move to remote and hybrid working, VPNs are increasingly relied on.

While having a ‘work from anywhere’ mentality is great for flexibility, remote access solutions, unfortunately, make a perfect entry point for an attacker, allowing them to logically position their device within that network. As a result, businesses must deploy thorough security measures, such as pushing VPN client software to end users or using full disk encryption technology to keep the infrastructure secure.

### How to manage vulnerabilities more effectively

With new vulnerabilities being discovered every day and old ones still needing to be patched, vulnerability management has never been more important. The best policies are a combination of automated technologies and effective team communication. While IT risk management software can help with this, procedures need to be in place to supplement technological capabilities.

##### So, what steps can businesses take?

**Regular cyber hygiene assessments:** Keep it simple. Consistently practicing basic cyber hygiene and regularly reviewing vulnerabilities can make a real impact on a business’s overall security strategy. This includes keeping on top of patches, frequently reviewing the technical estate, or even looking to invest in tools such as vulnerability software for continuous screening capabilities.

**Asset management:** When taking stock of possible at-risk endpoints, companies shouldn’t just review well-documented machines. The problem is often legacy hardware that has been long forgotten. Instead, the company should assess its entire infrastructure to properly identify areas for improvement. From there, they need to evaluate the impact each device would have if it were compromised and then categorically work to minimize the risk.

**Engage your senior leadership team:** Many reports discuss how password and basic cyber hygiene are commonly quite poor among executives and CEOs. This is problematic because the higher up in an organization someone is, the more sensitive the material they have access to. To remedy this, companies need to create tailored training sessions that inform senior figures on what their specific attack path is and how they can actively protect themselves.

**Threat modeling**: This will provide higher levels of visibility and allow organizations to see what an attacker sees. With this insight, organizations can build on this and deploy controls defensively along that attack path, creating in-depth layered defence models.

**Create canary accounts:** Companies should create canary accounts to put account credentials in files or in databases that are specifically set up to never be used. This will offer higher visibility and allow businesses to conduct a single form of monitoring.

**Air gapping: **Another exercise businesses can leverage is having file backups on a completely isolated device that cannot establish an external connection, a technique known as air gapping. This means that if a business does fall victim to an attack, hackers can’t gain access to its backup data since it is in no way connected to the main network. This will put the company in a much stronger position during the recovery window.

SureCloud’s Cyber Risk Management Capability can help you to build a clear view of vulnerabilities and the business-critical applications they impact while looking at the steps needed to mitigate any damage. We offer a combination of IT risk management software to bolster your cybersecurity, as well as expert cyber services and vulnerability assessments.

Related Posts

## You may also like this

[Similar Articles](https://csacyber.com/blog)

[![](https://csacyber.com/hs-fs/hubfs/20230510-N1005919-Edit1.jpg?width=624&height=427&name=20230510-N1005919-Edit1.jpg)](https://csacyber.com/blog/fluidone-group-appoints-charly-davis-as-managing-director-of-csa-cyber-to-advance-its-security-first-strategy)

 August 24, 2026

 2 min read

### [FluidOne Group appoints Charly Davis as Managing Director of CSA Cyber to advance its security-first strategy](https://csacyber.com/blog/fluidone-group-appoints-charly-davis-as-managing-director-of-csa-cyber-to-advance-its-security-first-strategy)

 Experienced industry leader joins FluidOne to strengthen integrated cyber, IT and secure networking...

[![CSA Cyber](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Stacked.png?width=40&height=40&name=CSA%20Cyber%20Logo%20FNL_Stacked.png) CSA Cyber](https://csacyber.com/blog/author/csa-cyber)

[![](https://csacyber.com/hs-fs/hubfs/Untitled%20design.jpg?width=624&height=427&name=Untitled%20design.jpg)](https://csacyber.com/blog/csa-cyber-and-fluidone-named-as-suppliers-on-g-cloud-15)

 August 20, 2026

 2 min read

### [CSA Cyber and FluidOne named as suppliers on G-Cloud 15](https://csacyber.com/blog/csa-cyber-and-fluidone-named-as-suppliers-on-g-cloud-15)

 CSA Cyber (CSA), part of the FluidOne Group, has been named as a supplier on Government Commercial...

[![CSA Cyber](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Stacked.png?width=40&height=40&name=CSA%20Cyber%20Logo%20FNL_Stacked.png) CSA Cyber](https://csacyber.com/blog/author/csa-cyber)

[![](https://csacyber.com/hs-fs/hubfs/Engineered%20to%20Endure%20Campaign%20Assets%20(2).png?width=624&height=427&name=Engineered%20to%20Endure%20Campaign%20Assets%20(2).png)](https://csacyber.com/blog/why-organisations-lose-security-visibility-without-realising-it)

 August 20, 2026

 6 min read

### [Why organisations lose security visibility without realising it](https://csacyber.com/blog/why-organisations-lose-security-visibility-without-realising-it)

 Before an organisation can understand risk, maintain control or respond effectively to emerging...

[![CSA Cyber](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Stacked.png?width=40&height=40&name=CSA%20Cyber%20Logo%20FNL_Stacked.png) CSA Cyber](https://csacyber.com/blog/author/csa-cyber)

[![CSA Cyber Logo FNL_Full Logo](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Full%20Logo.png?width=3463&height=1248&name=CSA%20Cyber%20Logo%20FNL_Full%20Logo.png "CSA Cyber Logo FNL_Full Logo")](https://csacyber.com/)

Established in 2013, Cyber Security Associates Limited trading as CSA Cyber provides cyber consultancy and cyber managed services which help to detect, protect and educate against the ever-changing cyber threat. We have built our team from a foundation of Government (ex-Military) and Commercially experienced specialists all holding current and relevant cyber certifications. Today our core services are based around a 24/7 Security Operations Centre (SOC) based in Gloucester.

#### News & Resources

- [Blog](https://csacyber.com/blog)
- [Case Studies](https://csacyber.com/case-studies)
- [Downloads & Reports](https://csacyber.com/downloads-and-reports)
- [Webinars](https://csacyber.com/webinars)
- [Careers](https://csacyber.com/careers)
- [Cyber Bundles (IT MSPs)](https://csacyber.com/cyber-bundles)

#### Quick Links

- [About Us](https://csacyber.com/about-us)
- [Certifications](https://csacyber.com/certifications-and-awards)
- [Our Parent Company](https://www.fluidone.com)
- [Partners](https://csacyber.com/partners)
- [Contact Us](https://csacyber.com/contact-us)
- [Anti Bribery Policy](https://csacyber.com/hubfs/CSAAnti-BriberyPolicy.pdf)
- [Complaints Policy](https://csacyber.com/hubfs/CSAComplaintsPolicy.pdf)
- [Corporate Social Responsibility Policy](https://csacyber.com/hubfs/CSACorporateSocialResponsibilityPolicy.pdf)
- [Slavery and Human Trafficking Statement](https://csacyber.com/hubfs/CSASlaveryandHumanTraffickingStatement.pdf)
- [NCSC CHECK Status Verification](https://www.ncsc.gov.uk/organisation/csa-cyber/check-penetration-testing)
- [CREST Approved Certification Verification](https://www.crest-approved.org/member_companies/csa-cyber/)

#### Contact Information

**United Kingdom - London**

Cyber Security Associates Ltd

5 Hatfields, London, SE1 9PG

 

**United Kingdom - Gloucester**

Cyber Security Associates Ltd

Unit 11, Wheatstone Court, Waterwells Business Park, GL2 2AQ

 

**Phone:** [+44(0) 300 303 4691](tel:03003034691)

**Email:** [hello@csacyber.com](mailto:hello@csacyber.com)

 

**United States of America**

Cyber Security Associates Inc.

6010 W. Spring Creek Pkwy, Plano, Texas, 75024

 

**Phone:** [+1 469 750 1695](tel:14697501695) 

**Email:** [hello@csacyber.com](mailto:hello@csacyber.com)

 

[![trust-pilot](https://csacyber.com/hs-fs/hubfs/trust-pilot.png?width=178&height=104&name=trust-pilot.png)](https://uk.trustpilot.com/review/csa.limited)

 

---

- [Website Terms of Use](https://csacyber.com/website-terms-of-use)
- [Website Privacy Policy](https://csacyber.com/privacy-notice)
- [Website Cookie Policy](https://csacyber.com/cookie-policy)

 Copyright 2026. Cyber Security Associates Ltd [Follow us on Facebook](https://www.facebook.com/CSALIMITED/) [Follow us on LinkedIn](https://www.linkedin.com/company/csa-cyber/) [Follow us on Twitter](https://twitter.com/cybersecurityis) [Follow us on Facebook](https://www.youtube.com/@cybersecurityassociateslim) [Follow us on Facebook](https://www.instagram.com/cybersecurityassociates)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Cyber Security Associates",
    "url" : "https://csacyber.com/blog/author/cyber-security-associates"
  },
  "dateModified" : "2024-12-07T13:53:35.074Z",
  "datePublished" : "2022-09-24T04:30:00.000Z",
  "headline" : "Successful Vulnerability Management: The Must-Know Vulnerabilities Your Business Needs to Fix",
  "image" : [ "https://csacyber.com/hubfs/vm1.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://csacyber.com/blog/successful-vulnerability-management-the-must-know-vulnerabilities-your-business-needs-to-fix",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://csacyber.com/hubfs/csacyber-logo-black-01.svg"
    },
    "name" : "Cyber Security Associates Ltd"
  }
}
```