NSA publishes a report of the top 25 vulnerabilities with patches available that are currently being found and exploited by “Chinese state-sponsored hackers”
NSA urges US public and private sector to apply patches or mitigations to prevent attacks.
Context & Ripple Effects
The NSA's top-25 list lands a month after CISA warned that hacking groups tied to China's Ministry of State Security were already inside US government networks via bugs in F5, Citrix, Pulse Secure, and Microsoft Exchange — all flaws with patches available. The new report reframes those intrusions as a pattern: Chinese state-sponsored hackers overwhelmingly favor known, unpatched vulnerabilities over novel exploits.
It also fits a longer arc. A 2018 report found China backdating entries in its own vulnerability disclosure database, suggesting state hackers deliberately bank unpatched flaws, and the Mandiant review of 2022 zero-day exploitation later confirmed Chinese groups led in exploiting bugs across Apple, Microsoft, and Google products. The NSA's move is the defensive mirror image: publish the target list so defenders can close it.
First-order effects
- US public- and private-sector network operators now have a ranked, actionable patching priority from the NSA — the named vendors whose products appear on the list face immediate pressure to confirm patches and push customers to apply them.
- Organizations that had deferred patching on the listed flaws lose the ambiguity excuse: the NSA has publicly confirmed these specific bugs are under active exploitation by Chinese state-sponsored hackers.
Second-order effects
- CISA and the FBI, already coordinating with the NSA on joint advisories like the 2022 warning about China-backed hackers snooping on network traffic, are pushed toward a shared playbook of prioritized advisories rather than one-off alerts.
- Vendors of the affected products — the same F5, Citrix, Pulse Secure, and Microsoft ecosystems CISA flagged — face customer audits and procurement questions about patch cadence, making time-to-patch a competitive differentiator in government-adjacent sales.
Third-order effects
- The pattern points toward institutionalized patch mandates: CISA's later catalog of known exploited vulnerabilities with binding deadlines for federal agencies extends the NSA's advisory model from 'please patch' to 'must patch on a clock'.
- If state-sponsored attackers keep concentrating on known-but-unpatched flaws, vulnerability economics shift — defenders who close the top-25 tail cheaply force attackers back toward costlier zero-days, raising the price of state-grade intrusion.
The trend: US cyber agencies are converging on prioritized, deadline-driven patching of known exploited vulnerabilities as the primary counter to Chinese state-sponsored intrusion campaigns.