Can a single unpatched library turn a phone into an entry point for espionage or fraud? This question matters now more than ever. H1 2025 saw disclosed CVEs climb 16% to 23,667, and many flaws came with public proof-of-concept code or required no authentication.
In this short introduction we explain why older software and Android ecosystems still face active risk. We link rising disclosure volume to real-world exposure: more CVEs, more public PoCs, and faster paths to remote compromise.
Expect concise examples and practical steps. The full piece blends telemetry, vendor advisories, and threat research to show how a single weak component can pivot into broad data loss or device takeover.
We keep urgency measured and guidance actionable so engineers and leaders can prioritize fixes that reduce real risk.
Key Takeaways
- Outdated components amplify security risk across devices and servers.
- Public PoCs and unauthenticated flaws shorten defender reaction time.
- Android apps with old SDKs are a common vector for mobile fraud.
- Mapping Known Exploited Vulnerabilities helps prioritize patches.
- Small, repeatable controls reduce exposure while full fixes roll out.
Executive context: why legacy and outdated apps remain prime targets in the United States
Outdated components concentrate risk where organizations least expect it: on public-facing apps, edge appliances, and mobile builds.This section explains who should read the findings and how aging stacks turn small bugs into major incidents for business owners and IT teams.
When vendors stop patching code, attackers treat those systems as low-effort, high-reward targets. Public disclosures and telemetry show nearly half of CISA’s Known Exploited Entries trace back to end-of-service software. That pattern raises the odds an exposed asset becomes a breach vector.
![]()
Who should read this and why it matters
Security leaders, platform management, and business owners need clear priorities. SMB operators and CISOs will get practical steps to reduce immediate exposure. Practitioners in operations and engineering gain actionable checkpoints for patching and compensating controls.
How aging software amplifies impact across enterprises
Unsupported stacks accumulate flaws fast—roughly 218 new issues every six months after support ends. Exploitation of known flaws already rivals stolen credentials as an initial access method in U.S. incidents. The result: a single unpatched component can force emergency fixes, cause downtime, and expose sensitive data.
| Metric | Value | Business implication |
|---|---|---|
| KEV entries linked to end-of-service | ~46% | Higher discovery by attackers; prioritize EOL assets |
| Post-support defects (6 months) | ~218 | Rapid defect accumulation increases exploit windows |
| Incidents with known-exploit initial access | 20% (Verizon) | Known issues are a common attack path for enterprises |
Methodology and sources used for this analysis
We combined CISA KEV updates, vendor advisories, and sensor telemetry into a reproducible source trail. That mix gave us clear, time‑bound data to prioritize fixes and measure real-world activity.
Our approach started with KEV additions (PHPMailer CVE‑2016‑10033, Zimbra CVE‑2019‑9621, Ruby on Rails CVE‑2019‑5418, MRLG CVE‑2014‑3931, and Citrix NetScaler CVE‑2025‑5777).

CISA KEV, vendor research, and telemetry-driven intelligence
We correlated KEV entries with vendor bulletins and exploitation telemetry from PAN‑OS (CVE‑2024‑3400), ScreenConnect (CVE‑2024‑1709), and Citrix (CVE‑2023‑4966).
Botnet tracking—EnemyBot, Sysrv‑k, Andoryu, AndroxGh0st, RondoDox—provided concrete signs of scanning and wget-based payload chains.
- Data sources: KEV catalog changes, vendor advisories, curated feeds.
- Tools: open-source signatures (Nuclei templates) and sensor logs for reproducibility.
- Focus: CVE identifiers, PoC availability, patch status, and exploitation counts to guide action.
Timeliness matters: where public PoCs appeared, exploitation rose quickly, so our process flags those windows for rapid response and practical mitigation.
H1 2025 vulnerability exploitation at a glance: volume, PoCs, and ease of abuse
H1 2025 made one thing clear: public proof‑of‑concepts and unauthenticated flaws shortened defenders’ windows for action. High disclosure volume plus easy exploit paths meant attackers converted notices into active attacks faster than in prior years.
The first half of the year recorded 23,667 cves, a 16% rise year‑over‑year, and 161 were confirmed exploited in the wild.

16% rise in CVEs and 161 exploited vulnerabilities: what the numbers mean
Recorded Future flagged 25 more exploited cases than KEV during this period, showing public feeds can outpace official lists.
Disclosures jumped; so did operational risk. With 42% of exploited vulnerabilities tied to public PoCs, defenders faced compressed patch windows and more hands‑on attempts.
Unauthenticated, remote, and RCE: attacker preferences quantified
Attackers favored reach: 69% of exploited cases required no authentication and 48% were remotely exploitable. Thirty percent allowed remote code execution, making rapid compromise possible.
- High-value targets: Microsoft products accounted for 28 exploited CVEs; edge and gateway appliances made up 17% of hits.
- Malware trends: Command‑and‑control activity dominated, backdoors followed, and Cobalt Strike remained common.
- Operational takeaway: prioritize scanning and patching for internet‑facing application endpoints and management interfaces to shrink the attack surface.
legacy vulnerability report analysis exploits targeting
Mapping old CVEs to current attack activity shows where stale systems still give attackers an easy foothold. This section links KEV entries to telemetry so teams can convert vague risk into prioritized fixes.
The KEV additions for PHPMailer (CVE‑2016‑10033), Zimbra SSRF (CVE‑2019‑9621), Rails path traversal (CVE‑2019‑5418), and MRLG (CVE‑2014‑3931) remind us that patched code can remain exploitable in production.

Telemetry from NetScaler, PAN‑OS, and ScreenConnect showed scanning and active exploitation tied to these IDs. That activity makes it urgent for organizations to map KEV items to their CMDB.
- Inventory mapping: match CVE IDs to services to turn abstract risk into action.
- Edge focus: appliances and gateways often reveal the first signs of chainable compromise.
- Mitigation: apply patches where possible and add compensating controls—segmentation and WAF rules—when upgrades stall.
Intelligence alignment matters: cross-reference KEV, vendor advisories, and your asset management to prioritize platforms that would cause the most damage if breached.
Legacy CVEs back in the spotlight: PHPMailer, Zimbra, Ruby on Rails, and MRLG
These four cases show how old fixes can remain active threats when outdated releases keep running in production. They teach a simple rule: a published patch only reduces risk when it reaches every affected system.
Years after fixes, some well-known flaws keep showing up in real-world attacks.
Active exploitation despite long-standing patches
PHPMailer (CVE-2016-10033), patched in 2016, still appears in incident telemetry and was added to KEV due to ongoing abuse.
Zimbra (CVE-2019-9621) and Rails (CVE-2019-5418) were fixed in 2019 yet reemerged in the wild.
Operational exposure in web application and infrastructure contexts
MRLG (CVE-2014-3931) shows how a decade-old buffer overflow can persist in looking glass tools. These are not theoretical risks; they affect real operations and internal networks.
- Key takeaway: templating and input handling bugs often become code execution or file disclosure when old releases remain.
- Mitigation: combine version upgrades with monitoring and strict internal network controls.
| Component | Patching year | Common impact |
|---|---|---|
| PHPMailer | 2016 | Command injection / code execution |
| Zimbra | 2019 | SSRF leading to internal access |
| Ruby on Rails | 2019 | Path traversal / file disclosure |
| MRLG | 2014 | Buffer overflow in network tools |
“Don’t assume age equals safety — assume unmaintained equals exposed.”

Android under fire: outdated Android apps and mobile-first fraud trends
Mobile malware rose in sophistication during H1 2025, and apps with old components were a key enabler. Two new techniques—virtualization overlays and NFC relay—let attackers steal credentials and payments at scale.

Banking trojans now chain UI overlays with backend services to convert stolen sessions into cash. Overlays hijack screens and capture OTPs while relay platforms turn phones into payment proxies.
Banking trojans, virtualization overlays, and NFC relay abuse
Eleven new mobile strains appeared in H1 2025; nine remained active. Attackers favor overlays that mimic legitimate application screens.
These overlays pair with permission abuse and accessibility features to gain access quickly. NFC relay attacks let fraudsters complete contactless payments without physical cards.
How outdated SDKs, libraries, and EOL components widen the attack surface
Outdated SDKs and end-of-life libraries inside applications drag known issues into many apps at once.
Third-party kits delay fixes across platforms. Developers often inherit risk when vendor updates stop but apps stay installed and active.
- Tactics: dropper apps, sideloading, social engineering to get initial access.
- Operations: overlays capture credentials; back-end services broker stolen sessions and cash out.
- Practical steps: enforce SDK minimums, run integrity checks, and add server-side anomaly detection for suspicious session activity.
- Detection: instrument behavior analytics to spot overlay artifacts, emulator footprints, and NFC timing anomalies.
“Rapid detection and coordinated takedown break the monetization chain and protect user accounts.”
Botnets and malware leveraging old flaws: EnemyBot, Sysrv‑k, Andoryu, AndroxGh0st, and RondoDox
These families show how simple chains still yield large, persistent botnet infrastructure. Operators mix brute force, known CVEs, and small downloader scripts to convert weak devices into service nodes fast.
Criminal groups reuse old web and CMS bugs to get initial code execution on servers and home gear. EnemyBot and Sysrv‑k hit Spring Cloud Gateway (CVE‑2022‑22947). Andoryu abused GitLab Exiftool (CVE‑2021‑22205). AndroxGh0st relied on PHPUnit (CVE‑2017‑9841).

From IoT to CMS: how wget-based payloads enable fast enrollment
The common chain is scan, exploit, then fetch a shell via wget or curl. That downloader drops multi-architecture binaries for ARM, MIPS, and x86. IoT botnets also abused Eir D1000 (CVE‑2016‑10372).
How compromised routers and DVRs become proxy and DDoS nodes
Fortinet documented RondoDox using TBK DVR (CVE‑2024‑3721) and Four‑Faith routers (CVE‑2024‑12856). Operators pivot these hosts into proxy farms and DDoS-for-hire services.
- Repeatable playbook: scan → exploit → wget/curl → enroll for DDoS or proxying.
- Wide reach: multi-architecture payloads lower development costs and speed spread.
- Defender actions: block downloader patterns, watch unusual outbound connections, and patch exposed appliances.
| Botnet | Primary CVE | Typical role |
|---|---|---|
| EnemyBot / Sysrv‑k | CVE‑2022‑22947 | Bot enrollment / DDoS |
| Andoryu | CVE‑2021‑22205 | CMS compromise / downloader |
| AndroxGh0st | CVE‑2017‑9841 | Server backdoor / proxy node |
| RondoDox | CVE‑2024‑3721, CVE‑2024‑12856 | Proxy infrastructure / fraud flows |
“Block common downloader patterns and monitor outbound anomalies to stop enrollment at scale.”
Edge and gateway devices as initial access: Ivanti, Citrix NetScaler, F5, and PAN‑OS
Edge appliances often act as the short path from the internet to a company’s crown jewels. When a gateway fails, attackers can turn authentication and decryption services into a springboard for wide‑scale compromise.
H1 2025 telemetry shows about 17% of exploited CVEs hit edge and gateway products. Examples include Ivanti Connect Secure (CVE‑2025‑0282), F5 BIG‑IP (CVE‑2023‑46747), Citrix NetScaler (CVE‑2023‑4966; CVE‑2025‑5777), and PAN‑OS GlobalProtect (CVE‑2024‑3400).
Why do perimeter appliances concentrate risk for organizations?
Perimeter devices terminate VPNs, decrypt traffic, and broker trust. That concentration gives a single exploited flaw the power to open internal network paths and expose services.
- Privileged paths: compromise yields lasting access to internal infrastructure and sensitive data.
- High reward for attackers: one exploit can expand the attack surface across many systems.
- Blind spots: appliances often sit outside endpoint monitoring, letting adversaries stage malware and data exfiltration.
- Operational fixes: enforce tight patch cadences, restrict management interfaces, require MFA and IP allowlists for admin access.
- Detection hardening: add telemetry on appliance health, session anomalies, and config changes; use segmentation and virtual patching when upgrades lag.
Treat edge gear as high‑value assets in your security program. Give them separate SLAs and out‑of‑band verification after critical updates to reduce overall risk.
PRE‑NVD and early warning signals: tracking issues before broad disclosure
PRE‑NVD signals give teams a head start on triage and temporary controls before mass scanning begins. Early open-source chatter and social feeds often surface actionable information that mature programs can turn into protective steps.
Security teams that act on early intelligence beat attackers by buying time and reducing impact.
Our platform saw pre-NVD alerts for SUSE Linux Enterprise (CVE-2025-6018), PHP SOAP Extension (CVE-2025-6491), Moodle (CVE-2025-49517), and Trend Micro Password Manager (CVE-2025-52837).
We aggregate over 100 open-source alerts weekly from social channels and OSINT sources. This stream gives development and application owners early information to plan safe updates without breaking production.
- Quick wins: stage WAF rules, restrict features, or tighten access while awaiting an official release.
- Process: validate source credibility, document risk, and notify system owners fast.
- Integration: feed PRE‑NVD findings into development and change windows so fixes fit normal deployment cadence.
Track when provisional information becomes assigned CVE IDs and confirm whether new advisories change severity or exploitability.
“Early signals let you treat raw data as a lead, not panic — validate, prioritize, and act.”
The web application weak points that persist: XSS, SQLi, and missing authorization
Simple web mistakes keep causing disproportionate harm. Cross-Site Scripting (CWE-79), SQL Injection (CWE-89), and Missing Authorization (CWE-862) led H1 2025 web incident share.
Many incidents still start with a missing authorization check or an unsanitized input field in a public web form.
What this means for application security, code, and development lifecycles
Fundamental web flaws dominate root causes, which points to gaps in secure coding and validation practices. ATT&CK T1190 (Exploit Public-Facing Application) showed up in roughly 73% of actively exploited CVEs.
Treat XSS and SQLi as symptoms, not the entire problem. Fixes require input validation, output encoding, and parameterized queries. Missing authorization often yields data exposure as fast as a memory bug.
- Embed security: add SAST/DAST and dependency scans into CI pipelines to catch issues early.
- Practical tactics: enforce least privilege, strict schema checks, and use secure-by-default frameworks.
- Developer focus: run abuse-case tests and adopt secure helper libraries to reduce coding errors.
| Weakness | Typical impact | Developer fix |
|---|---|---|
| XSS (CWE-79) | Session theft, UI fraud | Output encoding, CSP |
| SQLi (CWE-89) | Data exposure, privilege escalation | Parameterized queries, ORM use |
| Missing Authorization (CWE-862) | Unauthorized data access | Centralized checks, role testing |
“Small code fixes and repeatable patterns stop most web attacks before they become incidents.”
Risk management playbook for outdated Android apps and legacy systems
Start by mapping what you run today so risk becomes a manageable backlog, not a surprise incident. This section gives a concise playbook teams can follow to reduce exposure and sustain hygiene across applications and infrastructure.
Asset inventory, KEV mapping, and prioritized patch/upgrade planning
Visibility first: create an asset inventory tied to EOL/EOS status and map KEV-listed items to services you run.
Prioritize by exposure and business impact: internet-facing and mobile application components with public PoCs go to the top of the queue.
Compensating controls: segmentation, virtual patching, and WAF
When you can’t patch immediately: deploy segmentation, virtual patching, WAF rules, and strict access policies to reduce blast radius.
Rate limiting and tight admin allowlists often stop automated attacks while a scheduled patch is prepared.
Continuous observability, threat intelligence, and cross‑team governance
Operationalize monitoring: integrate tools that track software versions, certificate health, and anomalous outbound activity on edge and mobile back ends.
Governance: use shared dashboards so security, IT, and development teams manage remediation, measure mean time to patch, and cut EOL assets over time.
| Action | Goal | Tools | Metric |
|---|---|---|---|
| Inventory & KEV mapping | Reduce unknown assets | CMDB, scanner | % assets mapped |
| Risk-based patching | Lower exploit risk | Patch manager | Mean time to patch |
| Compensating controls | Limit access and attack surface | WAF, segmentation | Incidents from old software |
| Observability & governance | Sustain hygiene | SIEM, dashboards | EOL assets reduced (%) |
“Start with visibility, prioritize by exposure, and defend with layered controls.”
Conclusion
The pace of disclosures and rapid weaponization in early 2025 compressed defenders’ windows and showed how small flaws scale into wide impact. Acting fast on visibility, disciplined patching, and simple compensating controls reduces the attack surface and buys time for safer upgrades.
This report highlights clear examples—PHPMailer, Zimbra, Rails, MRLG—and shows how outdated software and edge devices keep access paths open for attackers. Teams that keep inventories, watch for early signals, and apply quick shields cut incident risk.
Make reduction a continuous program: measure outcomes, align fixes with business priorities, and monitor activity to catch new attack patterns before they cause data loss.