Mastodon Mastodon Mastodon Mastodon

Exploited in the Wild

Updated: · CyberSecureFox Editorial Team

Exploited in the wild means that a vulnerability is being used by real attackers against real victims, as opposed to being exploited only in a lab, a demo or a proof of concept.

What “in the wild” means

Security advisories describe a vulnerability’s status in stages. A flaw may be known only to the vendor, have public details, have a public proof of concept or, most seriously, be exploited in the wild (ITW). Vendors use cautious wording such as “Microsoft is aware of exploitation” or “Google is aware that an exploit exists in the wild”. When exploitation starts before a patch is available, the bug is a zero-day; when it starts after the patch, it is called an n-day.

Evidence of in-the-wild exploitation comes from incident response cases, threat intelligence, honeypots, telemetry from security products and crash reports.

Why it matters

A severity score alone does not show urgency. A medium-rated bug that attackers actively use is often more dangerous than a critical one nobody exploits. That is why the US Cybersecurity and Infrastructure Security Agency (CISA) has maintained the Known Exploited Vulnerabilities (KEV) catalog since November 2021, and federal agencies must fix listed flaws within set deadlines under Binding Operational Directive 22-01. Many organisations use KEV, together with CVSS and the EPSS probability score, to decide what to fix first. Mass exploitation of a single flaw, such as Log4Shell in 2021 or the MOVEit Transfer bug in 2023, can affect thousands of organisations within days.

How to respond to exploited vulnerabilities

  • Track the KEV catalog and vendor advisories and treat “exploited” flags as top priority in patch management.
  • If a patch is not yet available, apply vendor mitigations or take the system off the internet.
  • After patching, hunt for signs of earlier compromise – attackers may already be inside.
  • Reduce exposure of edge devices such as VPNs and firewalls, which are frequent targets.
Synonyms:
in-the-wild exploitation, actively exploited vulnerability