In cybersecurity, vulnerabilities are commonly grouped into four main types based on where the weakness exists.
- Network vulnerabilities are weaknesses in network infrastructure and protocols, such as unsecured wireless access points, open ports, outdated firmware on routers and firewalls, or unencrypted traffic.
- Operating system vulnerabilities are flaws in the OS itself, including unpatched software, default accounts, and excessive privileges, that attackers use to gain access or escalate control.
- Process vulnerabilities, also called procedural vulnerabilities, arise from weak or missing security procedures, such as poor password policies, inadequate access reviews, or inconsistent patching.
- Human vulnerabilities stem from user behavior, including susceptibility to phishing and social engineering, misuse of credentials, and configuration errors.
The four types frequently overlap in real attacks. A phishing email may deliver malware that exploits an unpatched operating system flaw, spreads across a flat network, and goes undetected because of a weak monitoring process. Treating the four types as connected parts of the same attack surface, rather than as separate problems owned by separate teams, gives a more accurate picture of actual risk.
