CVEs Surge 30% in 2024, Only 0.91% Weaponized
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-43208 | Unauthenticated Deserialization RCE in NextGen Healthcare Mirth Connect CVE-2023-43208 is an unauthenticated remote code execution flaw in NextGen Healthcare Mirth Connect, a widely used healthcare integration engine, caused by incomplete patching of the earlier CVE-2023-37679 deserialization vulnerability. An attacker can trigger it by sending crafted serialized data to the network-exposed Mirth Connect service, requiring no authentication or user interaction (CVSS 3.1: 9.8, AV:N/AC:L/PR:N/UI:N). Successful exploitation yields arbitrary code execution on the server, giving attackers a foothold in hospital and health-system networks that Mirth Connect uses to move clinical data (including PHI) between systems. All deployments running Mirth Connect versions before 4.4.1 are affected. The flaw is being actively exploited — CISA added it to the Known Exploited Vulnerabilities catalog on 2024-05-20 with known ransomware use, public proof-of-concept exploits exist, and EPSS estimates an 82.7% chance of exploitation within 30 days. Do: Upgrade Mirth Connect to version 4.4.1 or later as the CISA KEV required action, or discontinue use if upgrades are unavailable. Identify and restrict internet-exposed Mirth Connect instances (the service is commonly reachable on its web/admin interface), and hunt for signs of compromise given confirmed ransomware use. Because this bypasses the earlier CVE-2023-37679 fix, verify patch levels directly rather than assuming prior remediation. | 9.8 | 83% | KEV ransomware PoC ×2 |
| large≈10,000–30,000 internet-exposed Mirth Connect instances, plus many more internal deployments at thousands of hospitals and health systems |
Full article371 words · extracted from infosecurity-magazine.com · click to collapse
In the first half of 2024, the number of reported Common Vulnerabilities and Exposures (CVEs) has increased by 30% compared to last year, totaling 22,254. However, just 0.91% of reported CVEs were weaponized, according to Qualys.
This figure, highlighted in Qualys’ 2024 Midyear Threat Landscape Review, underscores the increasing complexity of the cybersecurity landscape and the growing need for enhanced protection measures.
The report, published today, suggests that this significant rise in vulnerabilities is driven by the advancing complexity of software and the pervasive use of technology, necessitating more dynamic and advanced vulnerability management strategies.
The review emphasizes the critical threat posed by the weaponization of vulnerabilities. Although only 0.91% (204 vulnerabilities) of the reported CVEs have been weaponized, these represent the most severe risks, frequently exploited through ransomware and other malware by threat actors.
Notably, there’s been a 10% increase in the weaponization of older CVEs in 2024, indicating a persistent danger from previously identified vulnerabilities.
According to the report, public-facing applications and remote services are the primary targets for initial access and lateral movement within networks. Exploiting these vectors allows attackers to infiltrate systems and move laterally, posing significant security risks. For example, CVE-2023-43208, which impacts healthcare systems, illustrates how vulnerabilities in critical sectors can have widespread and severe consequences.
Read more on tackling these threats: How to Build Cyber Resilience in Healthcare
Ransomware continues to be a prominent threat, according to the report, with six major vulnerabilities linked to ransomware campaigns. Additionally, three out of ten of the most exploited vulnerabilities in the last year were from Ivanti.

The Qualys findings underscore the necessity of leveraging and integrating threat intelligence with vulnerability management tools. By prioritizing actively exploited vulnerabilities and conducting regular scans, companies can enhance their security posture.
“Organizations must ensure regular updates, diligent patch management, and advanced threat detection systems are in place to mitigate the risks associated with high-critical vulnerabilities,” the company wrote.
“We strongly recommend that organizations conduct risk assessments and adopt a comprehensive approach to vulnerability management. Prioritize addressing vulnerabilities actively exploited in the wild (such as CISA KEV), those with a high likelihood of exploitation and those for which weaponized exploit code is available.”
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/cves-surge-30-2024/