Executive Summary
In March 2026, Qualys released a comprehensive analysis of over one billion remediation records from the Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog, spanning 10,000 organizations over four years. The study revealed that despite a 6.5-fold increase in remediation efforts since 2022, 63% of critical vulnerabilities remained unpatched after seven days, up from 56% in previous years. Alarmingly, 88% of 52 high-profile weaponized vulnerabilities were patched slower than they were exploited, with half being weaponized before any patch was available. This indicates a systemic failure in current vulnerability management practices to keep pace with the rapid exploitation timelines of threat actors. The findings underscore the urgent need for organizations to adopt autonomous, closed-loop risk operations to effectively mitigate vulnerabilities in real-time. The traditional manual remediation processes are proving inadequate against the accelerating threat landscape, necessitating a paradigm shift towards automated and proactive security measures.
Why This Matters Now
The rapid acceleration of vulnerability exploitation, often before patches are available, highlights the critical need for organizations to transition from manual remediation processes to automated, real-time risk management strategies to effectively combat emerging cyber threats.
Attack Path Analysis
An attacker exploited a known vulnerability in an unpatched system to gain initial access. They then escalated privileges by exploiting misconfigured IAM roles, allowing broader access. Utilizing these elevated privileges, the attacker moved laterally across the network, accessing sensitive systems. They established a command and control channel to maintain persistence and exfiltrated sensitive data. Finally, the attacker deployed ransomware, encrypting critical data and disrupting operations.
Kill Chain Progression
Initial Compromise
Description
The attacker exploited a known vulnerability in an unpatched system to gain initial access.
Related CVEs
CVE-2025-20333
CVSS 9.9A buffer overflow vulnerability in Cisco Secure Firewall ASA and FTD VPN Web Server allows remote code execution.
Affected Products:
Cisco Secure Firewall Adaptive Security Appliance (ASA) – 9.12, 9.13, 9.14
Cisco Secure Firewall Threat Defense (FTD) – 6.4, 6.5, 6.6
Exploit Status:
exploited in the wildCVE-2025-20362
CVSS 8.6A missing authorization vulnerability in Cisco Secure Firewall ASA and FTD VPN Web Server allows unauthorized access.
Affected Products:
Cisco Secure Firewall Adaptive Security Appliance (ASA) – 9.12, 9.13, 9.14
Cisco Secure Firewall Threat Defense (FTD) – 6.4, 6.5, 6.6
Exploit Status:
exploited in the wildCVE-2025-10585
CVSS 9.8A type confusion vulnerability in Google Chromium V8 engine allows remote code execution.
Affected Products:
Google Chromium – < 92.0.4515.159
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Exploitation of Remote Services
Exploitation for Privilege Escalation
Exploitation for Defense Evasion
External Remote Services
Exploitation for Client Execution
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities by installing applicable vendor-supplied security patches.
Control ID: 6.2
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.5
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Asset Management
Control ID: Pillar 3: Devices
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Information Technology/IT
Critical vulnerability management gaps expose IT infrastructure to autonomous AI-powered attacks exploiting Spring4Shell, Cisco IOS XE with remediation lagging 266+ days behind weaponization.
Financial Services
Manual remediation processes create cumulative exposure risks violating PCI DSS compliance requirements while AI-accelerated threats exploit banking infrastructure faster than human-scale defense responses.
Health Care / Life Sciences
HIPAA compliance frameworks inadequate against negative-day exploits targeting medical devices and patient data systems requiring autonomous risk operations to address vulnerability remediation backlogs.
Government Administration
CISA KEV analysis reveals federal agencies cannot remediate critical vulnerabilities before AI-powered exploitation, necessitating autonomous security fabric deployment to protect sensitive government infrastructure.
Sources
- Analysis of one billion CISA KEV remediation records exposes limits of human-scale securityhttps://www.bleepingcomputer.com/news/security/analysis-of-one-billion-cisa-kev-remediation-records-exposes-limits-of-human-scale-security/Verified
- CISA Known Exploited Vulnerabilities Cataloghttps://www.cisa.gov/known-exploited-vulnerabilities-catalogVerified
- CISA warns exploited Cisco flaws are a serious risk, so patch nowhttps://www.techradar.com/pro/security/cisa-warns-exploited-cisco-flaws-are-a-serious-risk-so-patch-nowVerified
- The Broken Physics of Remediationhttps://blog.qualys.com/vulnerabilities-threat-research/2026/03/23/the-broken-physics-of-remediationVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have constrained the attacker's lateral movement and data exfiltration, thereby reducing the overall impact.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While Aviatrix Zero Trust CNSF may not prevent initial exploitation, it could limit the attacker's ability to move laterally or access sensitive systems post-compromise.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust Segmentation could likely limit the attacker's ability to leverage escalated privileges to access unauthorized resources.
Control: East-West Traffic Security
Mitigation: Aviatrix East-West Traffic Security could likely reduce the attacker's ability to move laterally between workloads.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Multicloud Visibility & Control could likely detect and constrain unauthorized command and control communications.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Egress Security & Policy Enforcement could likely limit the attacker's ability to exfiltrate data.
While Aviatrix Zero Trust CNSF may not prevent the deployment of ransomware, it could likely limit the spread and impact by restricting lateral movement and isolating affected workloads.
Impact at a Glance
Affected Business Functions
- Network Security Operations
- Web Services Management
Estimated downtime: 7 days
Estimated loss: $500,000
Potential exposure of sensitive network configurations and user credentials.
Recommended Actions
Key Takeaways & Next Steps
- • Implement a robust vulnerability management program to ensure timely patching of known vulnerabilities.
- • Enforce least privilege access controls and regularly audit IAM roles to prevent privilege escalation.
- • Deploy east-west traffic security measures to monitor and control lateral movement within the network.
- • Establish comprehensive threat detection and anomaly response capabilities to identify and respond to command and control activities.
- • Implement egress security and policy enforcement to monitor and control data exfiltration attempts.



