The UK’s National Cyber Security Centre (NCSC) has issued a fresh alert about the growing number of cyber-attackers exploiting previously unknown vulnerabilities to compromise networks.
In a new advisory, the NCSC, along with partners from Australia, Canada, New Zealand and the US, shared a list of the top 15 routinely exploited vulnerabilities of 2023.
Among the products being targeted from vendors such as Cisco, Microsoft, and Fortinet, the attacks range from code injection and remote code execution, to authentication bypass and improper access control.
Of these vulnerabilities, the majority were first exploited as zero-days – weaknesses that were recently discovered and where a fix or patch was not immediately available from the vendor – which allowed threat actors to orchestrate attacks against higher-priority targets.
The advisory urges network defenders to stay on top of their vulnerability management processes and make sure all security updates are applied quickly across every asset in their networks.
It also encourages tech vendors and developers to adopt secure-by-design principles in their products, reducing the chances of vulnerabilities cropping up and being exploited down the line. That includes a recommendation to set up secure software development practices, like peer code reviews, and configuring products to have the most secure settings by default.
All of the vulnerabilities listed in this latest advisory have already had patches and fixes made available from vendors to mitigate the risk of compromise, with organisations encouraged to check whether they might be affected.
The trend in cyber-attackers exploiting zero-day weaknesses, which the NCSC said it has continued to observe into 2024, marks a shift from 2022 when less than half of the top list comprised these vulnerabilities.
Ollie Whitehouse, NCSC chief technology officer, said: “More routine initial exploitation of zero-day vulnerabilities represents the new normal which should concern end-user organisations and vendors alike as malicious actors seek to infiltrate networks.
“We urge network defenders to be vigilant with vulnerability management, have situational awareness in operations and call on product developers to make security a core component of product design and life-cycle to help stamp out this insidious game of whack-a-mole at source.”
In addition to the top list, the advisory also details a further 32 vulnerabilities that were routinely exploited in 2023, and were found in products targeted from large scale vendors like Microsoft, Atlassian, and Apple, which saw weaknesses across its iOS and Wallet systems.
Recommended reading
- Report: Half of Dark Web Posts Exploit Zero-Day Vulnerabilities
- Cisco Warns of Dangerous Zero-day in IOS XE
- Google Report Reveals 50% Surge in Zero-Day Vulnerabilities
The NCSC said that organisations should have a process in place to install vendor updates after they become available to minimise the opportunity for attackers, pointing to its own vulnerability management guidance which also advocates testing fixes before they go live to ensure no weak spots.
Similar advice also came from the US Cybersecurity and Infrastructure Security Agency (CISA), which further added that end users should enforce phishing-resistant MFA across their organisations, configure access controls using the principle of ‘least privilege’, and implement Zero Trust Network Architecture.





