# CWE-287: Improper Authentication

**Likelihood of exploit:** High · **KEV-linked**

> As of 2026-10-05, CWE-287 (Improper Authentication) underlies 72 CVEs tracked by Threadlinqs, 20 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 243 tracked threats. MITRE rates its likelihood of exploit as High.

**Last updated:** 2026-10-05

## What is CWE-287?

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

CWE-287 is a class-level weakness in MITRE’s Common Weakness Enumeration, with a MITRE likelihood of exploit of High. Applicable platforms: Language: Not Language-Specific; Operating_System: Not OS-Specific; Technology: Not Technology-Specific; Technology: Web Based; Technology: ICS/OT.

_Source: [MITRE CWE](https://cwe.mitre.org/data/definitions/287.html) (CWE-287 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data._

## Consequences

- **Integrity, Confidentiality, Availability, Access Control** — Read Application Data, Gain Privileges or Assume Identity, Execute Unauthorized Code or Commands. This weakness can lead to the exposure of resources or functionality to unintended actors, possibly providing attackers with sensitive information or even execute arbitrary code.

_Source: MITRE CWE, common consequences._

## How CWE-287 is exploited in the wild

Threadlinqs maps 72 CVEs to CWE-287, published between 2017-05-06 and 2026-09-27. 20 are listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild, and 11 are tied to ransomware campaigns. By CVSS v3 severity the set splits into 33 critical, 21 high, 12 medium, 1 low. The highest EPSS score in the set is 99.9% (CVE-2022-40684), the modelled probability of exploitation in the next 30 days. 243 tracked threats reference CWE-287 directly or through a CVE it covers; the most recent is “The First 24 Hours of a Ransomware Intrusion: Exfiltration, Credential Theft and Backup Targeting (Akira, REDBIKE, AGENDA)” (2026-10-03). Affected products concentrate in Microsoft (6), Solarwinds (4), Cisco (3), among 50 vendors in total.

## Vulnerabilities (CVEs)

Showing 40 of 72 CVEs mapped to CWE-287, CISA KEV first, then by CVSS score.

- [CVE-2026-20182](https://intel.threadlinqs.com/cve/CVE-2026-20182) — CISA KEV · CVSS 10 critical · EPSS 77.3% · published 2026-05-14
- [CVE-2021-22893](https://intel.threadlinqs.com/cve/CVE-2021-22893) — CISA KEV · CVSS 10 critical · EPSS 47.1% · published 2021-04-23
- [CVE-2026-20127](https://intel.threadlinqs.com/cve/CVE-2026-20127) — CISA KEV · CVSS 10 critical · EPSS 39.6% · published 2026-02-25
- [CVE-2025-32975](https://intel.threadlinqs.com/cve/CVE-2025-32975) — CISA KEV · CVSS 10 critical · EPSS 0.1% · published 2025-06-24
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684) — CISA KEV · CVSS 9.8 critical · EPSS 99.9% · published 2022-10-18
- [CVE-2023-35078](https://intel.threadlinqs.com/cve/CVE-2023-35078) — CISA KEV · CVSS 9.8 critical · EPSS 94.4% · published 2023-07-25
- [CVE-2017-7921](https://intel.threadlinqs.com/cve/CVE-2017-7921) — CISA KEV · CVSS 9.8 critical · EPSS 94.2% · published 2017-05-06
- [CVE-2018-10561](https://intel.threadlinqs.com/cve/CVE-2018-10561) — CISA KEV · CVSS 9.8 critical · EPSS 93.3% · published 2018-05-04
- [CVE-2025-61882](https://intel.threadlinqs.com/cve/CVE-2025-61882) — CISA KEV · CVSS 9.8 critical · EPSS 89.3% · published 2025-10-05
- [CVE-2019-19006](https://intel.threadlinqs.com/cve/CVE-2019-19006) — CISA KEV · CVSS 9.8 critical · EPSS 21.6% · published 2019-11-21
- [CVE-2026-65400](https://intel.threadlinqs.com/cve/CVE-2026-65400) — CISA KEV · CVSS 9.8 critical · EPSS 0.7% · published 2026-08-06
- [CVE-2026-16232](https://intel.threadlinqs.com/cve/CVE-2026-16232) — CISA KEV · CVSS 9.1 critical · EPSS 1.0% · published 2026-07-22
- [CVE-2020-0688](https://intel.threadlinqs.com/cve/CVE-2020-0688) — CISA KEV · CVSS 8.8 high · EPSS 94.3% · published 2020-02-11
- [CVE-2026-32201](https://intel.threadlinqs.com/cve/CVE-2026-32201) — CISA KEV · CVSS 8.8 high · EPSS 8.9% · published 2026-04-14
- [CVE-2024-53704](https://intel.threadlinqs.com/cve/CVE-2024-53704) — CISA KEV · CVSS 8.2 high · EPSS 95.1% · published 2025-01-09
- [CVE-2023-46805](https://intel.threadlinqs.com/cve/CVE-2023-46805) — CISA KEV · CVSS 8.2 high · EPSS 94.3% · published 2024-01-12
- [CVE-2025-61884](https://intel.threadlinqs.com/cve/CVE-2025-61884) — CISA KEV · CVSS 7.5 high · EPSS 97.5% · published 2025-10-12
- [CVE-2024-37085](https://intel.threadlinqs.com/cve/CVE-2024-37085) — CISA KEV · CVSS 6.8 medium · EPSS 75.6% · published 2024-06-25
- [CVE-2025-49706](https://intel.threadlinqs.com/cve/CVE-2025-49706) — CISA KEV · CVSS 6.5 medium · EPSS 99.0% · published 2025-07-08
- [CVE-2023-20867](https://intel.threadlinqs.com/cve/CVE-2023-20867) — CISA KEV · CVSS 3.9 low · EPSS 2.7% · published 2023-06-13
- [CVE-2026-41679](https://intel.threadlinqs.com/cve/CVE-2026-41679) — CVSS 10 critical · EPSS 2.9% · published 2026-04-23
- [CVE-2025-55241](https://intel.threadlinqs.com/cve/CVE-2025-55241) — CVSS 10 critical · EPSS 1.5% · published 2025-09-04
- [CVE-2026-100886](https://intel.threadlinqs.com/cve/CVE-2026-100886) — CVSS 10 critical · published 2026-09-27
- [CVE-2023-49105](https://intel.threadlinqs.com/cve/CVE-2023-49105) — CVSS 9.8 critical · EPSS 11.0% · published 2023-11-21
- [CVE-2026-46817](https://intel.threadlinqs.com/cve/CVE-2026-46817) — CVSS 9.8 critical · EPSS 0.6% · published 2026-05-28
- [CVE-2026-85984](https://intel.threadlinqs.com/cve/CVE-2026-85984) — CVSS 9.8 critical · EPSS 0.6% · published 2026-09-26
- [CVE-2026-28323](https://intel.threadlinqs.com/cve/CVE-2026-28323) — CVSS 9.8 critical · EPSS 0.6% · published 2026-07-30
- [CVE-2026-53483](https://intel.threadlinqs.com/cve/CVE-2026-53483) — CVSS 9.8 critical · EPSS 0.6% · published 2026-07-07
- [CVE-2026-60367](https://intel.threadlinqs.com/cve/CVE-2026-60367) — CVSS 9.8 critical · EPSS 0.5% · published 2026-07-22
- [CVE-2026-82329](https://intel.threadlinqs.com/cve/CVE-2026-82329) — CVSS 9.8 critical · EPSS 0.3% · published 2026-08-28
- [CVE-2026-55652](https://intel.threadlinqs.com/cve/CVE-2026-55652) — CVSS 9.8 critical · EPSS 0.3% · published 2026-07-15
- [CVE-2026-7664](https://intel.threadlinqs.com/cve/CVE-2026-7664) — CVSS 9.8 critical · EPSS 0.2% · published 2026-06-22
- [CVE-2026-5270](https://intel.threadlinqs.com/cve/CVE-2026-5270) — CVSS 9.8 critical · EPSS 0.2% · published 2026-07-14
- [CVE-2026-20129](https://intel.threadlinqs.com/cve/CVE-2026-20129) — CVSS 9.8 critical · EPSS 0.1% · published 2026-02-25
- [CVE-2026-23813](https://intel.threadlinqs.com/cve/CVE-2026-23813) — CVSS 9.8 critical · EPSS 0.0% · published 2026-03-11
- [CVE-2024-23470](https://intel.threadlinqs.com/cve/CVE-2024-23470) — CVSS 9.6 critical · EPSS 1.9% · published 2024-07-17
- [CVE-2024-23471](https://intel.threadlinqs.com/cve/CVE-2024-23471) — CVSS 9.6 critical · EPSS 1.5% · published 2024-07-17
- [CVE-2026-82107](https://intel.threadlinqs.com/cve/CVE-2026-82107) — CVSS 9.6 critical · EPSS 0.3% · published 2026-09-10
- [CVE-2026-62144](https://intel.threadlinqs.com/cve/CVE-2026-62144) — CVSS 9.1 critical · EPSS 1.0% · published 2026-07-22
- [CVE-2026-73501](https://intel.threadlinqs.com/cve/CVE-2026-73501) — CVSS 9.1 critical · published 2026-08-12

## Affected vendors

- [Microsoft](https://intel.threadlinqs.com/vendors/microsoft) — 6 CVEs
- [Solarwinds](https://intel.threadlinqs.com/vendors/solarwinds) — 4 CVEs
- [Cisco](https://intel.threadlinqs.com/vendors/cisco) — 3 CVEs
- **Oracle Corporation** — 3 CVEs
- [Apache Software Foundation](https://intel.threadlinqs.com/vendors/apache-software-foundation) — 2 CVEs
- [IBM](https://intel.threadlinqs.com/vendors/ibm) — 2 CVEs
- [Ivanti](https://intel.threadlinqs.com/vendors/ivanti) — 2 CVEs
- [Rizwan17](https://intel.threadlinqs.com/vendors/rizwan17) — 2 CVEs
- [Vmware](https://intel.threadlinqs.com/vendors/vmware) — 2 CVEs
- [checkpoint](https://intel.threadlinqs.com/vendors/checkpoint) — 2 CVEs
- **cyberlord92** — 2 CVEs
- [jfrog](https://intel.threadlinqs.com/vendors/jfrog) — 2 CVEs

## Threat activity

243 tracked threats cite CWE-287; the 25 most recent are listed.

- [The First 24 Hours of a Ransomware Intrusion: Exfiltration, Credential Theft and Backup Targeting (Akira, REDBIKE, AGENDA)](https://intel.threadlinqs.com/threat/TL-2026-2852) — HIGH · 2026-10-03
- [Forgeable Session Cookie (Hard-Coded HMAC Secret) in Yard Management System Bypasses Entra ID MFA and Enables User and Admin Impersonation](https://intel.threadlinqs.com/threat/TL-2026-2892) — HIGH · 2026-10-02
- [Warlock Ransomware Attackers Hit Water and Telecom Operators via SharePoint ToolShell Exploitation (Longlegs / Storm-2603)](https://intel.threadlinqs.com/threat/TL-2026-2833) — CRITICAL · 2026-10-01
- [Microsoft Titan Analytics JWT 'alg:none' Authentication Bypass Exposed Access to 17.3 Trillion ClickHouse Rows](https://intel.threadlinqs.com/threat/TL-2026-2675) — HIGH · 2026-09-26
- [Nation-State Intrusions into Telecom Infrastructure via SS7, BGP Hijacking, and Router Compromise (Salt Typhoon)](https://intel.threadlinqs.com/threat/TL-2026-2649) — HIGH · 2026-09-25
- [NightEagle (APT-Q-95) Deploys GhostContainer Backdoor on Exchange, Exploits BlueKeep (CVE-2019-0708) and DCSync to Compromise Russian Active Directory](https://intel.threadlinqs.com/threat/TL-2026-2606) — CRITICAL · 2026-09-21
- [ShinyHunters Hacks Clop Ransomware Gang's Tor Leak Site via Grav CMS File Upload Flaw, Threatens 72-Hour Extortion](https://intel.threadlinqs.com/threat/TL-2026-2584) — MEDIUM · 2026-09-19
- [SolarWinds Access Rights Manager Hard-Coded Cryptographic Key (CVE-2026-28326) Enables Unauthenticated RCE](https://intel.threadlinqs.com/threat/TL-2026-2585) — CRITICAL · 2026-09-19
- [Apple Ships 273-CVE Coordinated Security Update Across iOS 27, macOS, watchOS, tvOS, visionOS, Safari, and Xcode — Bundles a Previously KEV-Listed Pre-Auth Screen Sharing RCE](https://intel.threadlinqs.com/threat/TL-2026-2522) — CRITICAL · 2026-09-15
- [TELUS Warns Customers of 16-Month Account Takeover Breach via Compromised Credentials](https://intel.threadlinqs.com/threat/TL-2026-2491) — MEDIUM · 2026-09-14
- [Dell ObjectScale Critical Deserialization Flaw (CVE-2026-70416, CVSS 10.0) Enables Unauthenticated RCE](https://intel.threadlinqs.com/threat/TL-2026-2475) — CRITICAL · 2026-09-13
- [Dutch NCSC Warns of Critical Check Point VPN Flaws (CVE-2026-85102, CVE-2026-85103) — Exploitation Expected Imminently](https://intel.threadlinqs.com/threat/TL-2026-2463) — CRITICAL · 2026-09-12
- [Nation-State and Financially Motivated Actors Weaponize Claude AI Multi-Agent Frameworks for Automated Cyberattacks and Data Theft](https://intel.threadlinqs.com/threat/TL-2026-2466) — CRITICAL · 2026-09-12
- [September 2026 Microsoft Patch Tuesday — Record 966+ Vulnerabilities with Two Actively Exploited Zero-Days (CVE-2026-81963, CVE-2026-85880) and Multiple Critical Wormable RCEs](https://intel.threadlinqs.com/threat/TL-2026-2398) — CRITICAL · 2026-09-08
- [DragonForce Ransomware Attack on RubberMill, Inc. — ~340GB Data Exfiltration Including PII, Credentials, CAD Files with Defense Mil-Spec References](https://intel.threadlinqs.com/threat/TL-2026-2364) — CRITICAL · 2026-09-06
- [Chinese-Speaking Operator "Nie" Uses SecFlow AI Orchestration Framework (Claude, Qwen, DeepSeek) and GLUTTON Steganographic Webshell in Multi-Country Espionage Campaign](https://intel.threadlinqs.com/threat/TL-2026-2325) — HIGH · 2026-09-04
- [ORB Networks and Nation-State CNI Targeting: Destructive Wiper Attack on Polish Energy Infrastructure via Exposed FortiGate Devices](https://intel.threadlinqs.com/threat/TL-2026-2317) — HIGH · 2026-09-03
- [CVE-2026-82329: Critical JFrog Artifactory Authentication Bypass Exploited Days After Disclosure](https://intel.threadlinqs.com/threat/TL-2026-2287) — CRITICAL · 2026-09-01
- [Qilin-Linked Campaign Exploits MCP Gateway and LLM Framework Flaws (CVE-2026-59822, CVE-2026-42271, CVE-2026-48710) for RCE and Cryptomining](https://intel.threadlinqs.com/threat/TL-2026-2185) — CRITICAL · 2026-08-28
- [Suspected Chinese-Speaking Threat Actor Exploits ownCloud and WordPress Flaws to Steal Philippine Nuclear and Naval Data](https://intel.threadlinqs.com/threat/TL-2026-2172) — CRITICAL · 2026-08-27
- [Adobe and Nvidia Patch Dozens of Vulnerabilities Across Multiple Products, Including Two Critical Flaws in Nvidia's NemoClaw AI Agent Stack and a CVSS 10.0 Adobe Campaign Classic Chain](https://intel.threadlinqs.com/threat/TL-2026-2152) — CRITICAL · 2026-08-26
- [Edge Infrastructure Under Siege: Tenable and SentinelOne Datasets Reveal Convergent Nation-State and Criminal Exploitation of Perimeter Devices](https://intel.threadlinqs.com/threat/TL-2026-2153) — HIGH · 2026-08-26
- [Apache Tomcat 11.0.25 Fixes 11 Vulnerabilities Including HTTP/2 DoS, Authorization Bypass, and Auth Fail-Open Flaws — NVD Scores 5 of 11 CRITICAL/HIGH Despite Apache's Low/Moderate Ratings](https://intel.threadlinqs.com/threat/TL-2026-2159) — CRITICAL · 2026-08-26
- [2026 Ransomware Surge Targeting US Organizations: Identity-First Compromise, BYOVD, and Living-Off-the-Cloud Exfiltration (Qilin, Akira, Clop, INC Ransom, Play, DragonForce, Sinobi)](https://intel.threadlinqs.com/threat/TL-2026-2125) — HIGH · 2026-08-23
- [LockBit 5.0 Ransomware Extortion Claim Against US Bank (U.S. Bancorp)](https://intel.threadlinqs.com/threat/TL-2026-2094) — HIGH · 2026-08-21

## Mitigations

- **Architecture and Design / Libraries or Frameworks**: Use an authentication framework or library such as the OWASP ESAPI Authentication feature.

_Source: MITRE CWE, potential mitigations._

## Detection methods (MITRE CWE)

- **Automated Static Analysis** (effectiveness: Limited): Automated static analysis is useful for detecting certain types of authentication. A tool may be able to analyze related configuration files, such as .htaccess in Apache web servers, or detect the usage of commonly-used authentication libraries. Generally, automated static analysis tools have difficulty detecting custom authentication schemes. In addition, the software's design may include some functionality that is accessible to any user and does not require an established identity; an…
- **Manual Static Analysis** (effectiveness: High): This weakness can be detected using tools and techniques that require manual (human) analysis, such as penetration testing, threat modeling, and interactive tools that allow the tester to record and modify an active session. Manual static analysis is useful for evaluating the correctness of custom authentication mechanisms.
- **Manual Static Analysis - Binary or Bytecode** (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Binary / Bytecode disassembler - then use manual analysis for vulnerabilities & anomalies
- **Dynamic Analysis with Automated Results Interpretation** (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Web Application Scanner Web Services Scanner Database Scanners
- **Dynamic Analysis with Manual Results Interpretation** (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Fuzz Tester Framework-based Fuzzer
- **Manual Static Analysis - Source Code** (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Manual Source Code Review (not inspections)
- **Automated Static Analysis - Source Code** (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Source code Weakness Analyzer Context-configured Source Code Weakness Analyzer
- **Automated Static Analysis** (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Configuration Checker

_Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher._

## Related weaknesses

- [CWE-284 Improper Access Control](https://intel.threadlinqs.com/cwe/CWE-284)

Canonical: https://intel.threadlinqs.com/cwe/CWE-287
Source definition: https://cwe.mitre.org/data/definitions/287.html
Detection rules and IOCs for threats exploiting CWE-287 via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
