What is CWE-294?
A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).
Capture-replay attacks are common and can be difficult to defeat without cryptography. They are a subset of network injection attacks that rely on observing previously-sent valid commands, then changing them slightly if necessary and resending the same commands to the server.
CWE-294 is a base-level weakness in MITRE’s Common Weakness Enumeration, with a MITRE likelihood of exploit of High. Applicable platforms: Language: Not Language-Specific.
Source: MITRE CWE (CWE-294 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.
Consequences
- Access Control — Gain Privileges or Assume Identity. Messages sent with a capture-relay attack allow access to resources which are not otherwise accessible without proper authentication.
Source: MITRE CWE, common consequences.
How CWE-294 is exploited in the wild
Threadlinqs maps 7 CVEs to CWE-294, published between 2023-03-14 and 2026-09-08. 1 is listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild. By CVSS v3 severity the set splits into 1 critical, 2 high, 2 medium. The highest EPSS score in the set is 93.3% (CVE-2023-23397), the modelled probability of exploitation in the next 30 days. 43 tracked threats reference CWE-294 directly or through a CVE it covers; the most recent is “September 2026 Microsoft Patch Tuesday — Record 966+ Vulnerabilities with Two Actively Exploited Zero-Days (CVE-2026-81963, CVE-2026-85880) and Multiple Critical Wormable RCEs” (2026-09-08). Affected products concentrate in CoreWCF (2), Microsoft (1), Spring (1), among 5 vendors in total.
Vulnerabilities (CVEs)
All 7 CVEs mapped to CWE-294, CISA KEV first, then by CVSS score.
- CVE-2023-23397 — CISA KEV · CVSS 9.8 critical · EPSS 93.3% · published 2023-03-14
- CVE-2026-54783 — CVSS 7.4 high · EPSS 0.1% · published 2026-07-08
- CVE-2026-41707 — CVSS 7.4 high · published 2026-08-25
- CVE-2026-54779 — CVSS 5.9 medium · EPSS 0.2% · published 2026-07-08
- CVE-2026-82470 — CVSS 5.4 medium · published 2026-08-29
- CVE-2026-55250 — EPSS 0.5% · published 2026-09-08
- CVE-2026-86219 — EPSS 0.2% · published 2026-09-06
Affected vendors
Threat activity
43 tracked threats cite CWE-294; the 25 most recent are listed.
- September 2026 Microsoft Patch Tuesday — Record 966+ Vulnerabilities with Two Actively Exploited Zero-Days (CVE-2026-81963, CVE-2026-85880) and Multiple Critical Wormable RCEsCRITICAL
- Microsoft September 2026 Patch Tuesday — 999 CVEs, 3 actively exploited zero-days (CVE-2026-85880, CVE-2026-81963, CVE-2026-85046)CRITICAL
- Anthropic Locks Out Claude Users After Commodity Infostealers (Vidar, LummaC2, StealC, RedLine, Acreed, Atomic Stealer) Hijack Login SessionsMEDIUM
- Infostealer Malware (Vidar, LummaC2, StealC, RedLine, Acreed, Atomic Stealer) Hijacking Claude Login Sessions to Drain UsageMEDIUM
- Apache Tomcat 11.0.25 Fixes 11 Vulnerabilities Including HTTP/2 DoS, Authorization Bypass, and Auth Fail-Open Flaws — NVD Scores 5 of 11 CRITICAL/HIGH Despite Apache's Low/Moderate RatingsCRITICAL
- Mirage2FA Phishing-as-a-Service Surge Hits 4,532 US and EU Organizations, Abusing Microsoft 365 Login FlowsHIGH
- 91 Spring Framework CVEs Disclosed by Broadcom, Including Critical Deserialization Flaw CVE-2026-59285CRITICAL
- Russia (GRU Unit 26165 / APT28) Runs Multi-Vector Surveillance, Intimidation, Sabotage and Cyber Espionage Campaign Against Europe's Ukraine Defence Supply ChainHIGH
- Microsoft August 2026 Patch Tuesday: 400 Flaws Fixed, Including Lazarus-Exploited Zero-Day CVE-2026-68820 (AFD.sys) and Two Publicly Disclosed Zero-Days (CVE-2026-62832 "LegacyHive", CVE-2026-72971)CRITICAL
- WSUS NTLM Relay Attack Chain Enables Malicious Update Deployment via SUSDB Stored ProceduresHIGH
- UNC6671 Rebrands BlackFile into Redact, Pink, Helix, Falcon: Vishing + AiTM Campaign Steals M365/Okta Data for ExtortionHIGH
- AI-Generated Phishing Shifts to Malware-Free In-Browser AiTM Session TheftHIGH
- KARR Bluetooth Vulnerability Lets Nearby Attackers Unlock and Immobilize Over 2 Million CarsHIGH
- KARR Aftermarket Car Alarm Bluetooth Flaw Exposes 2.2M Vehicles to Remote Unlock and ImmobilizationHIGH
- German-Led Takedown of Kratos (SneakyLog/Sneaky 2FA) Phishing-as-a-Service Platform Bypassing MFA via AiTM Session-Cookie TheftHIGH
- German-US-Indonesian Law Enforcement Dismantle Kratos (aka SneakyLog / Sneaky 2FA) Phishing-as-a-Service Kit Targeting Microsoft 365 Sessions and MFAHIGH
- Kali365 Phishing-as-a-Service Kit Abuses Microsoft Device Code Authentication to Hijack Microsoft 365 AccountsHIGH
- EvilTokens Phishing-as-a-Service Kit Abuses Microsoft Device Code Authentication with AES-GCM "Ghost Code" to Breach Finance, Tech, and Managed Security FirmsHIGH
- Forg365: Telegram-Distributed Phishing-as-a-Service Abusing Microsoft Device-Code Flow and AiTM to Hijack Microsoft 365/Entra SessionsHIGH
- ARToken: Business Email Compromise-as-a-Service Platform Targeting Microsoft 365 (Cisco Talos / EvilTokens Affiliate)HIGH
- LastPass Customer CRM Data Exposed via Klue OAuth Token Theft (Icarus Salesforce Supply-Chain Campaign)MEDIUM
- CodeStorm AiTM Phishing Kit Abuses Compromised Microsoft 365 Accounts for Real-Time MFA-Bypass Account Takeover (Storm-1167 Overlap)HIGH
- EvilTokens Phishing-as-a-Service: Microsoft OAuth 2.0 Device Authorization Grant (Device Code) Phishing Against Microsoft 365HIGH
- Zscaler ThreatLabz 2026 Report: Encrypted Phishing & AiTM/BiTM Initial-Access Campaigns Targeting the Public SectorHIGH
- Roblox Developer Group Takeovers via Malicious 'robase' Python Package and Discord Job-Offer Social EngineeringHIGH
Mitigations
- Architecture and Design: Utilize some sequence or time stamping functionality along with a checksum which takes this into account in order to ensure that messages can be parsed only once.
- Architecture and Design: Since any attacker who can listen to traffic can see sequence numbers, it is necessary to sign messages with some kind of cryptography to ensure that sequence numbers are not simply doctored along with content.
Source: MITRE CWE, potential mitigations.