Vulnerabilities in the Wild
Based on what's making headlines and causing real pain for security teams right now, here are the critical vulnerabilities keeping us up at night.
Active Exploitation in the Wild
The Ivanti Connect Secure VPN vulnerabilities (CVE-2025-0282 and CVE-2025-0283) are being actively exploited right now. We're seeing threat actors chaining these to achieve unauthenticated remote code execution. If you've got Ivanti appliances, patch immediately — this is a "drop everything" situation.
The Apache Struts Saga Continues
Apache Struts has another critical RCE vulnerability (CVE-2024-53677) that's trivial to exploit. Given Struts' history and widespread deployment in enterprise Java applications, this is getting hammered. CVSS 9.5 for a reason.
Zero-Day Reality
We're still dealing with fallout from recent Chrome and Safari zero-days that were exploited in the wild before patches dropped. Browser vulnerabilities remain a prime attack vector, especially for targeted campaigns.
The Supply Chain Nightmare
The MOVEit Transfer vulnerability aftermath is still reverberating through organizations. We're seeing delayed breach notifications as companies discover they were impacted through third-party vendors. This has reinforced that supply chain visibility is abysmal in most environments.
Citrix Bleeding Edge
Citrix NetScaler ADC and Gateway have had multiple critical vulnerabilities this past year allowing unauthenticated access and code execution. These internet-facing appliances are juicy targets.
What I'm Actually Worried About
Honestly? The vulnerabilities that concern me most aren't necessarily the newest ones — it's the known criticals from 6-12 months ago that still aren't patched in production because of "business requirements" or change control bureaucracy. Log4Shell is still exploitable in countless environments almost three years later.
From your Splunk ES perspective, are you seeing any particular vulnerability trends in your detection data? The correlation between vuln scanner output and actual exploitation attempts can be pretty revealing.