Between 2021 and 2023, Code Execution and Injection was the most common Virtual Private Network (VPN) vulnerability, contributing to 23% of issues. There was a 92% spike in this type of vulnerability in 2023. Denial of Service Attacks and Information Disclosure and Data Leaks represented significant concerns, with 51 and 36 occurrences respectively. Other common vulnerabilities included Privilege Escalation and Authentication and Authorization Issues. Major affected vendors included Cisco, Zyxel, and Synology.

The NCSC wants developers to get serious on software security
The NCSC’s new Software Security Code of Practice has been praised by cyber professionals as a significant advancement in enhancing software supply chain security.