Threadlinqs IntelligenceStart free

Weakness · BaseCWE-295

CWE-295: Improper Certificate Validation

KEV-linkedBase

As of 2026-10-05, CWE-295 (Improper Certificate Validation) underlies 15 CVEs tracked by Threadlinqs, 2 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 34 tracked threats.

CVEs
15Mapped to CWE-295
CISA KEV
2Exploited in the wild
Critical
2CVSS v3 critical CVEs
Threats
34Tracked campaigns citing it
Likelihood
—MITRE likelihood of exploit

Last updated:

What is CWE-295?

The product does not validate, or incorrectly validates, a certificate.

CWE-295 is a base-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: Not Language-Specific; Technology: Not Technology-Specific; Technology: Web Based; Technology: Mobile.

Source: MITRE CWE (CWE-295 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.

Consequences

  • Integrity, Authentication — Bypass Protection Mechanism, Gain Privileges or Assume Identity. When a certificate is invalid or malicious, it might allow an attacker to spoof a trusted entity by interfering in the communication path between the host and client. The product might connect to a malicious host while believing it is a trusted host, or the product might be deceived into accepting spoofed data that appears to originate from a trusted host.

Source: MITRE CWE, common consequences.

How CWE-295 is exploited in the wild

Threadlinqs maps 15 CVEs to CWE-295, published between 2022-05-10 and 2026-10-04. 2 are listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild, and 1 is tied to ransomware campaigns. By CVSS v3 severity the set splits into 2 critical, 7 high, 1 medium, 2 low. The highest EPSS score in the set is 91.5% (CVE-2022-26923), the modelled probability of exploitation in the next 30 days. 34 tracked threats reference CWE-295 directly or through a CVE it covers; the most recent is “WatchGuard Fireware OS Critical Code Injection Vulnerability in BOVPN over TLS Client (CVE-2026-86131)” (2026-09-30). Affected products concentrate in Apple (1), Cisco (1), IBM (1), among 15 vendors in total.

Vulnerabilities (CVEs)

All 15 CVEs mapped to CWE-295, CISA KEV first, then by CVSS score.

Affected vendors

  • Apple — 1 CVE
  • Cisco — 1 CVE
  • IBM — 1 CVE
  • Kalkitech — 1 CVE
  • Microsoft — 1 CVE
  • WatchGuard — 1 CVE
  • alexpechkarev — 1 CVE
  • checkpoint — 1 CVE
  • cockpit-hq — 1 CVE
  • defunkt — 1 CVE
  • go-pay — 1 CVE
  • micro — 1 CVE

Threat activity

34 tracked threats cite CWE-295; the 25 most recent are listed.

Mitigations

  • Architecture and Design, Implementation: Certificates should be carefully managed and checked to assure that data are encrypted with the intended owner's public key.
  • Implementation: If certificate pinning is being used, ensure that all relevant properties of the certificate are fully validated before the certificate is pinned, including the hostname.

Source: MITRE CWE, potential mitigations.

Detection methods (MITRE CWE)

  • Automated Static Analysis - Binary or Bytecode (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Bytecode Weakness Analysis - including disassembler + source code weakness analysis Binary Weakness Analysis - including disassembler + source code weakness analysis
  • Manual Static Analysis - Binary or Bytecode (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Binary / Bytecode disassembler - then use manual analysis for vulnerabilities & anomalies
  • Dynamic Analysis with Automated Results Interpretation (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Web Application Scanner
  • Dynamic Analysis with Manual Results Interpretation (effectiveness: High): According to SOAR [REF-1479], the following detection techniques may be useful: Highly cost effective: Man-in-the-middle attack tool
  • Manual Static Analysis - Source Code (effectiveness: High): According to SOAR [REF-1479], the following detection techniques may be useful: Highly cost effective: Focused Manual Spotcheck - Focused manual analysis of source Manual Source Code Review (not inspections)
  • Automated Static Analysis - Source Code (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Source code Weakness Analyzer Context-configured Source Code Weakness Analyzer
  • Architecture or Design Review (effectiveness: High): According to SOAR [REF-1479], the following detection techniques may be useful: Highly cost effective: Inspection (IEEE 1028 standard) (can apply to requirements, design, source code, etc.)

Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.