CISA's latest review finds that the most exploited software vulnerabilities in 2024–2025 belong to decades-old weakness classes — such as injection flaws, improper input validation, and path traversal — that should have been eliminated long ago, with seven of the top ten most frequent vulnerabilities falling into MITRE's "stubborn" or "unforgivable" categories. The agency argues the problem is not technical complexity but failures in organizational culture, developer workflows, and slow adoption of Secure by Design (SBD) practices. CISA is urging software vendors to take ownership of security outcomes by eliminating these longstanding flaws at the development stage, rather than continuing to burden defenders with an endless cycle of patches.