Capital Cyber News
Reporting for United States defense contractors and small business KEV catalog 2026.08.14

Threats and Vulnerabilities

The Old Bugs That Never Stopped Working

Attackers do not always chase the newest exploit. Instead, they often reach for what already works: the legacy vulnerability. The CISA Known Exploited Vulnerabilities Catalog highlights this pattern, with old bugs resurfacing in attacks and new entries being added every week. If you want to stop these threats, asset inventory is the control that gives you a fighting chance.

What is a legacy vulnerability and why does it matter?

A legacy vulnerability is a security flaw in older software or systems that remains unpatched or in use long after its discovery. These are more than theoretical risks. CISA’s Known Exploited Vulnerabilities Catalog, which tracks real-world exploited weaknesses, added CVE-2009-0556 in Microsoft Office to its list as recently as January 7, 2026 (CISA Known Exploited Vulnerabilities Catalog, https://www.cisa.gov/known-exploited-vulnerabilities-catalog). This is a bug reported more than a decade ago, yet attackers still find it effective. On January 12, 2026, CISA added CVE-2025-8110 in Gogs, another example of attackers relying on what works, more than what is new.

With 1665 entries in the CISA catalog and 181 added since the start of 2026, the list continues to grow. The fact that a vulnerability from 2009 remains relevant shows that attackers do not need innovation when old vulnerabilities are still present in target environments.

Why do attackers keep using old vulnerabilities?

Attackers use what works. When old vulnerabilities remain unpatched or active in your environment, they offer an easy way in. CISA’s catalog is more than a historical record. Of the 1665 entries, 349 are flagged as having known ransomware campaign use. This means attackers are more than scanning for the latest headlines, they are actively using old bugs to compromise businesses.

The continued exploitation of legacy vulnerabilities often comes down to one thing: organizations have not found and eliminated them. Many companies lose track of what software is running where, especially as staff change or systems are phased out but not properly removed. Attackers know this and scan for these forgotten or neglected systems.

How do I know if I have a legacy vulnerability?

You cannot fix what you do not know you have. Asset inventory is your starting point. This control means keeping an up-to-date list of all devices, software, and systems in your environment. Without it, you cannot check whether you are exposed to a specific vulnerability, old or new.

For example, if you do not know an old version of Microsoft Office is still installed on a workstation, you will not know to check for CVE-2009-0556. Similarly, if a forgotten Gogs instance is running somewhere, CVE-2025-8110 remains a risk. Asset inventory is not a checkbox exercise. It is the foundation for patch management, vulnerability scanning, and every other security process.

What does CISA’s Known Exploited Vulnerabilities Catalog tell me?

CISA’s catalog is an authoritative source for vulnerabilities that are being used in real-world attacks. It is not based on theoretical risk. If a vulnerability is listed, it has been exploited somewhere. The catalog is updated regularly and includes information about whether a vulnerability has been used in ransomware campaigns. Since January 1, 2026, 181 new vulnerabilities have been added. This includes both newly discovered bugs and older ones that attackers are still using.

You can view the catalog and its updates at CISA’s Known Exploited Vulnerabilities Catalog.

What should I do on Monday to address legacy vulnerabilities?

Start with asset inventory. Make sure you know what is on your network and what software is installed on every device. This is the only way to check if you are exposed to a vulnerability in the CISA catalog. Once you have a current inventory, review it against the catalog’s entries. If you find software or systems listed, plan to update, patch, or remove them.

Asset inventory is not a one-time project. It requires regular updates as devices and software change. Assign responsibility for keeping the inventory current. Use it to guide your patch management and vulnerability scanning efforts.

What happens if I ignore legacy vulnerabilities?

Ignoring legacy vulnerabilities is risky. Attackers look for the easiest way in, and old, unpatched software is a favorite target. With hundreds of vulnerabilities in active use, including some flagged for ransomware campaigns, leaving a legacy vulnerability in your environment is inviting trouble.

CISA’s catalog shows that even bugs from more than a decade ago, like CVE-2009-0556 in Microsoft Office, can still be used by attackers. If you do not track and remediate these, you may be the next victim.

Common questions

What is the CISA Known Exploited Vulnerabilities Catalog? It is a list maintained by CISA of vulnerabilities that are known to be exploited in real-world attacks. The catalog includes details on each vulnerability and is updated regularly.

How often are legacy vulnerabilities added to the catalog? The catalog is updated as new evidence emerges of exploitation. This can include both newly discovered vulnerabilities and older ones, such as CVE-2009-0556, which was added in 2026 despite being reported years earlier.

Is asset inventory required for compliance frameworks like CMMC or NIST 800-171? Yes, asset inventory is a foundational control in these frameworks. You cannot achieve or maintain compliance without knowing what assets are in your environment.

Identify Persistent Vulnerabilities in Your Systems

If you are a defense contractor working toward CMMC or NIST 800-171 readiness, you may qualify for the Cyber Grants Alliance CMMC Gap Assessment Grant. This in kind grant is delivered as services and covers all 110 controls for qualifying defense contractors. Learn more at https://cybergrantsalliance.org/cmmc-gap-assessment-grant/.

The lesson is clear: attackers do not need new tricks when old ones still work. Make asset inventory your top priority, and you will be in a stronger position to find and fix the legacy vulnerabilities that never stopped working for attackers.

More on Threats

Threats · 4 min When Your IT Provider Is the Attack Path

Learn how the recent CVE-2026-18556 in N-able N-central highlights the risks of MSP supply chain attack and what you should ask your IT provider.