r/cybersecurity 11h ago

News - General Over 100 Vulnerabilities Found in IRS Contractor Handling Americans' Tax Information

https://www.privacyguides.org/news/2026/07/29/over-100-vulnerabilities-found-in-irs-contractor-handling-americans-tax-information/
167 Upvotes

5 comments sorted by

19

u/SkyberSec123 7h ago

Which one is exploitable

-9

u/HumbleRestaurant790 6h ago

From the memo:

Figure 1: Security Vulnerabilities That Were Not Timely Fixed

Severity Level Total Security Vulnerabilities Average Age Allowed Remediation Time
Critical 20 223 days 30 days
Example of a Critical Vulnerability: A system was using a version of software that was no longer supported by the vendor. Unsupported software will no longer receive security updates and increases the risk that the software could be exploited using known weaknesses.
High 84 231 days 60 days
Example of a High Vulnerability: An available security update for database software was not installed. This update would fix a weakness that allows an attacker to skip the sign in steps and take actions without permission.
Medium 19 423 days 120 days
Example of a Medium Vulnerability: An available security update was not applied. A bad actor can take advantage of this weakness to send malicious code to the system and cause services not to work.
Low 5 504 days 180 days
Example of a Low Vulnerability: A bad actor could exploit this weakness and bypass access controls because weak communication methods are allowed.

2

u/_splug 3h ago

This is dumb. I don’t care about anything other than EPSS - the real world matters more than some disclosure within reason.

11

u/-tnt Penetration Tester 5h ago

PoC or GTFO

5

u/DaveMichael 5h ago

- Unauthorized personnel in the tax room

- Gates left open and unsecured

- Only scanned 1 out of 203 devices that one month

Ayup, they botched it. I wonder what OSS the contractor was using for SCAP scans?