A method to assess 'forgivable' vs 'unforgivable' vulnerabilities
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Research from the NCSC designed to eradicate vulnerability classes and make the top-level mitigations easier to implement.
CSIRTS triage
- What
- Research aims to categorize vulnerability classes for easier mitigation.
- Who is affected
- Organizations managing vulnerabilities.
- Urgency
- Remediation is important for improving vulnerability management.
- Action
- Review the research findings for implementation.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://www.ncsc.gov.uk/report/a-method-to-assess-forgivable-vs-unforgivable-vulnerabilities
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2023-34362Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 99.9% of all EPSS-scored CVEs.
- Exploitation likely imminentCVE-2023-36934EPSS puts this in the most-targeted tier (95.2% 30-day exploitation probability). Prioritize alongside KEV items. Riskier than 99.9% of all EPSS-scored CVEs.
- Exploitation confirmedCVE-2023-27997Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 99.7% of all EPSS-scored CVEs.
- Exploitation confirmedCVE-2021-26084Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 99.9% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2023-34362 | coverage & exploitation status | NVD · CVE.org |
| CVE-2023-36934 | coverage & exploitation status | NVD · CVE.org |
| CVE-2023-27997 | coverage & exploitation status | NVD · CVE.org |
| CVE-2021-26084 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownexploitedPost-exploitation activities in Fortinet FortiGate (April 11, 2025)cert-fr-alerte
- criticalexploitedCVE-2023-27997: Fortinet FortiOS and FortiProxy SSL-VPN Heap-Based Buffer Overflow Vulnerabilitycisa-kev
- criticalexploitedCVE-2023-34362: Progress MOVEit Transfer SQL Injection Vulnerabilitycisa-kev
- criticalexploitedCVE-2021-26084: Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection …cisa-kev
Recent advisories for A method to
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-55099: icalendar is an RFC 5545 compatible parser and generator of iCalendar files for Python. From 7…nvd · 2026-08-25
- mediumCVE-2026-79772: Nokogiri versions before 1.19.1 fail to check the return value from xmlC14NExecute in the cano…nvd · 2026-08-25
- mediumCVE-2026-79771: Nokogiri versions before 1.19.3 contain a memory leak in the XSLT Stylesheet transform method …nvd · 2026-08-25
- mediumCVE-2026-55529: PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the MCP HTTP Stream _valid…nvd · 2026-08-25
- highCVE-2026-79659: Ech0 before 4.7.3 contains a server-side request forgery vulnerability in the fetchPeerConnect…nvd · 2026-08-25
- criticalCVE-2026-78683: NLTK before 3.10.0 (affected versions <=3.9.4) contains an unsafe pickle deserialization vulne…nvd · 2026-08-25
More from NCSC-UK Publications
- unknownManaging the cyber risk of agentic AI2026-08-20
- unknownHow BitLocker PINs help protect your data and devices2026-08-13
- unknownHelp shape the future of resilient private 5G2026-08-12
- unknownWater sector example added to the NCSC’s Secure connectivity principles2026-08-11
- unknownNCSC statement in response to recent incidents resulting from frontier AI evaluations2026-08-04