Threadlinqs IntelligenceStart free

Weakness · ClassCWE-287

CWE-287: Improper Authentication

Likelihood of exploit: HighKEV-linkedClass

As of 2026-10-05, CWE-287 (Improper Authentication) underlies 72 CVEs tracked by Threadlinqs, 20 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 243 tracked threats. MITRE rates its likelihood of exploit as High.

CVEs
72Mapped to CWE-287
CISA KEV
20Exploited in the wild
Critical
33CVSS v3 critical CVEs
Threats
243Tracked campaigns citing it
Likelihood
HighMITRE likelihood of exploit

Last updated:

What is CWE-287?

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

CWE-287 is a class-level weakness in MITRE’s Common Weakness Enumeration, with a MITRE likelihood of exploit of High. Applicable platforms: Language: Not Language-Specific; Operating_System: Not OS-Specific; Technology: Not Technology-Specific; Technology: Web Based; Technology: ICS/OT.

Source: MITRE CWE (CWE-287 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.

Consequences

  • Integrity, Confidentiality, Availability, Access Control — Read Application Data, Gain Privileges or Assume Identity, Execute Unauthorized Code or Commands. This weakness can lead to the exposure of resources or functionality to unintended actors, possibly providing attackers with sensitive information or even execute arbitrary code.

Source: MITRE CWE, common consequences.

How CWE-287 is exploited in the wild

Threadlinqs maps 72 CVEs to CWE-287, published between 2017-05-06 and 2026-09-27. 20 are listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild, and 11 are tied to ransomware campaigns. By CVSS v3 severity the set splits into 33 critical, 21 high, 12 medium, 1 low. The highest EPSS score in the set is 99.9% (CVE-2022-40684), the modelled probability of exploitation in the next 30 days. 243 tracked threats reference CWE-287 directly or through a CVE it covers; the most recent is “The First 24 Hours of a Ransomware Intrusion: Exfiltration, Credential Theft and Backup Targeting (Akira, REDBIKE, AGENDA)” (2026-10-03). Affected products concentrate in Microsoft (6), Solarwinds (4), Cisco (3), among 50 vendors in total.

Vulnerabilities (CVEs)

Showing 40 of 72 CVEs mapped to CWE-287, CISA KEV first, then by CVSS score.

  • CVE-2026-20182 — CISA KEV · CVSS 10 critical · EPSS 77.3% · published 2026-05-14
  • CVE-2021-22893 — CISA KEV · CVSS 10 critical · EPSS 47.1% · published 2021-04-23
  • CVE-2026-20127 — CISA KEV · CVSS 10 critical · EPSS 39.6% · published 2026-02-25
  • CVE-2025-32975 — CISA KEV · CVSS 10 critical · EPSS 0.1% · published 2025-06-24
  • CVE-2022-40684 — CISA KEV · CVSS 9.8 critical · EPSS 99.9% · published 2022-10-18
  • CVE-2023-35078 — CISA KEV · CVSS 9.8 critical · EPSS 94.4% · published 2023-07-25
  • CVE-2017-7921 — CISA KEV · CVSS 9.8 critical · EPSS 94.2% · published 2017-05-06
  • CVE-2018-10561 — CISA KEV · CVSS 9.8 critical · EPSS 93.3% · published 2018-05-04
  • CVE-2025-61882 — CISA KEV · CVSS 9.8 critical · EPSS 89.3% · published 2025-10-05
  • CVE-2019-19006 — CISA KEV · CVSS 9.8 critical · EPSS 21.6% · published 2019-11-21
  • CVE-2026-65400 — CISA KEV · CVSS 9.8 critical · EPSS 0.7% · published 2026-08-06
  • CVE-2026-16232 — CISA KEV · CVSS 9.1 critical · EPSS 1.0% · published 2026-07-22
  • CVE-2020-0688 — CISA KEV · CVSS 8.8 high · EPSS 94.3% · published 2020-02-11
  • CVE-2026-32201 — CISA KEV · CVSS 8.8 high · EPSS 8.9% · published 2026-04-14
  • CVE-2024-53704 — CISA KEV · CVSS 8.2 high · EPSS 95.1% · published 2025-01-09
  • CVE-2023-46805 — CISA KEV · CVSS 8.2 high · EPSS 94.3% · published 2024-01-12
  • CVE-2025-61884 — CISA KEV · CVSS 7.5 high · EPSS 97.5% · published 2025-10-12
  • CVE-2024-37085 — CISA KEV · CVSS 6.8 medium · EPSS 75.6% · published 2024-06-25
  • CVE-2025-49706 — CISA KEV · CVSS 6.5 medium · EPSS 99.0% · published 2025-07-08
  • CVE-2023-20867 — CISA KEV · CVSS 3.9 low · EPSS 2.7% · published 2023-06-13
  • CVE-2026-41679 — CVSS 10 critical · EPSS 2.9% · published 2026-04-23
  • CVE-2025-55241 — CVSS 10 critical · EPSS 1.5% · published 2025-09-04
  • CVE-2026-100886 — CVSS 10 critical · published 2026-09-27
  • CVE-2023-49105 — CVSS 9.8 critical · EPSS 11.0% · published 2023-11-21
  • CVE-2026-46817 — CVSS 9.8 critical · EPSS 0.6% · published 2026-05-28
  • CVE-2026-85984 — CVSS 9.8 critical · EPSS 0.6% · published 2026-09-26
  • CVE-2026-28323 — CVSS 9.8 critical · EPSS 0.6% · published 2026-07-30
  • CVE-2026-53483 — CVSS 9.8 critical · EPSS 0.6% · published 2026-07-07
  • CVE-2026-60367 — CVSS 9.8 critical · EPSS 0.5% · published 2026-07-22
  • CVE-2026-82329 — CVSS 9.8 critical · EPSS 0.3% · published 2026-08-28
  • CVE-2026-55652 — CVSS 9.8 critical · EPSS 0.3% · published 2026-07-15
  • CVE-2026-7664 — CVSS 9.8 critical · EPSS 0.2% · published 2026-06-22
  • CVE-2026-5270 — CVSS 9.8 critical · EPSS 0.2% · published 2026-07-14
  • CVE-2026-20129 — CVSS 9.8 critical · EPSS 0.1% · published 2026-02-25
  • CVE-2026-23813 — CVSS 9.8 critical · EPSS 0.0% · published 2026-03-11
  • CVE-2024-23470 — CVSS 9.6 critical · EPSS 1.9% · published 2024-07-17
  • CVE-2024-23471 — CVSS 9.6 critical · EPSS 1.5% · published 2024-07-17
  • CVE-2026-82107 — CVSS 9.6 critical · EPSS 0.3% · published 2026-09-10
  • CVE-2026-62144 — CVSS 9.1 critical · EPSS 1.0% · published 2026-07-22
  • CVE-2026-73501 — CVSS 9.1 critical · published 2026-08-12

Affected vendors

Threat activity

243 tracked threats cite CWE-287; the 25 most recent are listed.

Mitigations

  • Architecture and Design / Libraries or Frameworks: Use an authentication framework or library such as the OWASP ESAPI Authentication feature.

Source: MITRE CWE, potential mitigations.

Detection methods (MITRE CWE)

  • Automated Static Analysis (effectiveness: Limited): Automated static analysis is useful for detecting certain types of authentication. A tool may be able to analyze related configuration files, such as .htaccess in Apache web servers, or detect the usage of commonly-used authentication libraries. Generally, automated static analysis tools have difficulty detecting custom authentication schemes. In addition, the software's design may include some functionality that is accessible to any user and does not require an established identity; an…
  • Manual Static Analysis (effectiveness: High): This weakness can be detected using tools and techniques that require manual (human) analysis, such as penetration testing, threat modeling, and interactive tools that allow the tester to record and modify an active session. Manual static analysis is useful for evaluating the correctness of custom authentication mechanisms.
  • Manual Static Analysis - Binary or Bytecode (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Binary / Bytecode disassembler - then use manual analysis for vulnerabilities & anomalies
  • Dynamic Analysis with Automated Results Interpretation (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Web Application Scanner Web Services Scanner Database Scanners
  • Dynamic Analysis with Manual Results Interpretation (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Fuzz Tester Framework-based Fuzzer
  • Manual Static Analysis - Source Code (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Manual Source Code Review (not inspections)
  • Automated Static Analysis - Source Code (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Source code Weakness Analyzer Context-configured Source Code Weakness Analyzer
  • Automated Static Analysis (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Configuration Checker

Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.