OVERVIEW OF 2024 ● Number of reported vulnerabilities 2015–2024 40 000 40,008 30 00 25,043 20 000 14,643 10 000 0 6,487 6,447 2015 2016 2017 16,509 17,305 18,349 2018 2019 2020 Source: nvd.nist.gov Magento. Hundreds of notifications were also sent to owners of network devices and management systems with critical vulnerabilities. EXPLOITING A ZERO-DAY VULNERABILITY IN ESTONIA On 23 October, information about a zero-day vulnerability in FortiManager (CVE-202447575) was made public. This vulnerability in a critical FortiManager function allowed attackers to execute arbitrary commands within the system due to the absence of authentication. Fortinet had warned its clients about the potential vulnerability a few days earlier, advising them to update the software and implement additional protective measures. However, in Estonia, this vulnerability was already exploited on 22 October, with attackers gaining control of two servers belonging to one organisation. GLOBAL TRENDS In 2024, the number of reported vulnerabilities grew significantly. The number of reported vulnerabilities surged in 2024, reaching 40,008 globally – a one-third increase from the 28,817 identified in 2023. Global trends included the exploitation of zero-day vulnerabilities in the firmware of network devices and network management systems. For example, two zero-day vulnerabilities in Ivanti software (CVE-2023-46805 and CVE2024-21887) were exploited by groups linked to China. These vulnerabilities allowed attackers to bypass authentication and inject commands. CYBER SECURITY IN ESTONIA 2025 28,817 20,155 2021 2022 2023 2024 CERT-EE discovered a critical vulnerability in Palo Alto software CERT-EE identified and documented a critical vulnerability (CVE-2024-3393) in devices running Palo Alto Networks’ operating system, PAN-OS. The vulnerability allowed attackers to send a specially designed malicious network packet that caused the firewall to freeze, rendering it unusable in a denial-of-service state. When in a denial-of-service state, the firewall halts all network traffic, which disrupts internet connectivity and disables online services reliant on the network. Working in collaboration, CERT-EE and Palo Alto engineers identified the root cause of the issue, and Palo Alto released an updated version of PAN-OS to address the vulnerability. Cybercriminals also continued to target devices with older, known vulnerabilities, often exploiting them for ransomware attacks or adding them to botnets. As in previous years, numerous critical vulnerabilities were discovered in web content management systems and e-commerce software. The prevalence of zero-day vulnerabilities and the ongoing exploitation of older vulnerabilities highlight the need for a systematic approach to this issue. Organisations must establish and follow vulnerability management processes and bolster their network security with additional protective measures. ● 35

Select target paragraph3