Report analysis · ENISA Threat Landscape 2025
ENISA ranks exploited vulnerabilities sixth. From the patch queue, that undersells them.
ENISA's 2025 Threat Landscape catalogues 4,875 incidents across the EU between July 2024 and June 2025. Read it next to a vulnerability feed and one line stands out: “exploited vulnerabilities” sits sixth — behind DDoS, ransomware, data breaches, phishing and supply-chain compromise — and, unlike most of those, ENISA puts no number on it. That placement is right for what ENISA is measuring. It is also easy to misread if your job is deciding what to patch this week.
What the ranking actually measures
ENISA ranks by incident volume and disruption, not by root cause. DDoS tops the list at 77% of incidents — largely pro-Russia hacktivist collectives such as NoName057(16) generating huge volumes of individually low-impact traffic. Ransomware ranks second on impact despite a smaller share; phishing is the entry vector in about 60% of incidents; public administration absorbs 63% of them. It is an incident responder's ranking: what is hitting, how often, how hard.
Why sixth undersells it
“Exploited vulnerabilities” is not a peer of those categories — it is the layer beneath several of them. A ransomware incident that began with an exploited edge-device CVE is counted as ransomware. A data breach that started with an unpatched VPN is counted as a data breach. Rank by incident type and the enabler dissolves into the categories it enabled. That is not an ENISA error; it is what incident taxonomies do. But from the patch queue, “sixth, unquantified” is the wrong signal.
What the vulnerability data says
We hold 380,742 CVEs from ENISA's own EU Vulnerability Database. Of those, 1,648 are flagged as exploited — within a rounding error of the 1,674 on CISA's KEV list, two authorities that assemble their catalogues independently. And on 13,938 CVEs the EU and the US disagree on severity outright — the subject of our EU-vs-NVD page. The exploitation surface ENISA ranks sixth is, by these counts, both large and contested.
The actors ENISA highlights make the point from the other side. All five it named for 2025 — NoName057(16), UNC5221, Mustang Panda, APT41 and Flax Typhoon — are in our threat-actor catalogue (5/5 matched), and most run on the vulnerabilities they can reach: edge appliances, unpatched services, known-exploited CVEs. Even the DDoS that tops ENISA's chart needs infrastructure to launch from — very often, an exploited box.
Two lenses, one picture
This is why the site now switches its entire control view by region. ENISA's is an incident-and-impact lens, tuned for European defenders and their reporting obligations. NVD — and most vulnerability tooling — is a weakness-and-exploitability lens. Neither is complete. A European CISO reading only ENISA under-weights patch urgency; one reading only NVD under-weights the availability and hacktivist pressure that dominates EU incident volume. Set the region to EU on any CVE page and you get the ISO 27001 control mapping and the EU severity view beside the NVD one — the same reconciliation, applied one vulnerability at a time.
What we are not saying
Not that ENISA has it wrong. Its ranking is the right tool for prioritising incident response and shaping NIS2-era policy — jobs a CVE feed cannot do. The claim is narrower: exploited vulnerabilities look small in an incident-count ranking and large in an exploitation-and-severity one, and defenders need both numbers in view. The report is the map of what happened; the vulnerability data is the map of what is reachable. Read together, they are the same territory.
Source figures: ENISA Threat Landscape 2025 (CC BY 4.0). Our transcription + charts: the ENISA figures. More report analyses: global threat reports.
Published: 23 August 2026 00:24 UTC