What is CWE-295?
The product does not validate, or incorrectly validates, a certificate.
CWE-295 is a base-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: Not Language-Specific; Technology: Not Technology-Specific; Technology: Web Based; Technology: Mobile.
Source: MITRE CWE (CWE-295 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.
Consequences
- Integrity, Authentication — Bypass Protection Mechanism, Gain Privileges or Assume Identity. When a certificate is invalid or malicious, it might allow an attacker to spoof a trusted entity by interfering in the communication path between the host and client. The product might connect to a malicious host while believing it is a trusted host, or the product might be deceived into accepting spoofed data that appears to originate from a trusted host.
Source: MITRE CWE, common consequences.
How CWE-295 is exploited in the wild
Threadlinqs maps 15 CVEs to CWE-295, published between 2022-05-10 and 2026-10-04. 2 are listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild, and 1 is tied to ransomware campaigns. By CVSS v3 severity the set splits into 2 critical, 7 high, 1 medium, 2 low. The highest EPSS score in the set is 91.5% (CVE-2022-26923), the modelled probability of exploitation in the next 30 days. 34 tracked threats reference CWE-295 directly or through a CVE it covers; the most recent is “WatchGuard Fireware OS Critical Code Injection Vulnerability in BOVPN over TLS Client (CVE-2026-86131)” (2026-09-30). Affected products concentrate in Apple (1), Cisco (1), IBM (1), among 15 vendors in total.
Vulnerabilities (CVEs)
All 15 CVEs mapped to CWE-295, CISA KEV first, then by CVSS score.
- CVE-2022-26923 — CISA KEV · CVSS 8.8 high · EPSS 91.5% · published 2022-05-10
- CVE-2023-41991 — CISA KEV · CVSS 5.5 medium · EPSS 3.2% · published 2023-09-21
- CVE-2026-85102 — CVSS 9.8 critical · EPSS 0.3% · published 2026-09-09
- CVE-2026-20184 — CVSS 9.8 critical · EPSS 0.0% · published 2026-04-15
- CVE-2026-105216 — CVSS 7.4 high · published 2026-10-04
- CVE-2026-105218 — CVSS 7.4 high · published 2026-10-04
- CVE-2026-105221 — CVSS 7.4 high · published 2026-10-04
- CVE-2026-105222 — CVSS 7.4 high · published 2026-10-04
- CVE-2026-56820 — CVSS 7.4 high · published 2026-07-21
- CVE-2026-90647 — CVSS 7.4 high · published 2026-09-12
- CVE-2026-18173 — CVSS 3.7 low · EPSS 0.2% · published 2026-09-22
- CVE-2026-105217 — CVSS 3.1 low · published 2026-10-04
- CVE-2026-86131 — EPSS 0.3% · published 2026-09-29
- CVE-2026-7532 — EPSS 0.0% · published 2026-06-25
- CVE-2026-69248 — published 2026-08-03
Affected vendors
- Apple — 1 CVE
- Cisco — 1 CVE
- IBM — 1 CVE
- Kalkitech — 1 CVE
- Microsoft — 1 CVE
- WatchGuard — 1 CVE
- alexpechkarev — 1 CVE
- checkpoint — 1 CVE
- cockpit-hq — 1 CVE
- defunkt — 1 CVE
- go-pay — 1 CVE
- micro — 1 CVE
Threat activity
34 tracked threats cite CWE-295; the 25 most recent are listed.
- WatchGuard Fireware OS Critical Code Injection Vulnerability in BOVPN over TLS Client (CVE-2026-86131)CRITICAL
- Check Point Security Gateway VPN Pre-Auth RCE (CVE-2026-85102) and Management Path Traversal Zero-Day (CVE-2026-93616) Actively ExploitedCRITICAL
- CISA Adds Four Actively Exploited KEVs: Check Point Gateway/Management RCE Flaws, Arista VeloCloud Orchestrator Auth Bypass, F5 BIG-IP APM Heap OverflowCRITICAL
- Eclypsium InfraTrust Report: Mass Active Exploitation of Network Management Systems (Cisco FMC/ISE CVE-2026-20079, CVE-2026-76460; SonicWall SMA 1000 CVE-2026-83548/83549; Linux Kernel CopyFail CVE-2026-31431)CRITICAL
- SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems Drop a Persistent BackdoorCRITICAL
- Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM APE1808 Devices (SSA-864900) — Including Actively Exploited FortiCloud SSO Bypass (CVE-2025-59718/-59719) and FortiOS Heap Overflow (CVE-2025-25249)CRITICAL
- Dutch NCSC Warns of Critical Check Point VPN Flaws (CVE-2026-85102, CVE-2026-85103) — Exploitation Expected ImminentlyCRITICAL
- Adobe and Nvidia Patch Dozens of Vulnerabilities Across Multiple Products, Including Two Critical Flaws in Nvidia's NemoClaw AI Agent Stack and a CVSS 10.0 Adobe Campaign Classic ChainCRITICAL
- FirewallFalcon Manager: Supply-Chain Backdoor in Underground VPN Server InfrastructureCRITICAL
- Node.js Patches 11 Security Flaws Across v22.23.2, v24.18.1, v26.5.1 (HTTP/2 DoS, Permission Model Bypass, TLS/mTLS Issues)HIGH
- SleeperGem: RubyGems Supply Chain Attack Uses Hijacked Dormant Maintainer Accounts to Weaponize git_credential_manager, Dendreo, and fastlane-plugin-run_tests_firebase_testlabHIGH
- Critical ASUS Router Flaw (CVE-2026-13385) Enables MITM Arbitrary Command ExecutionCRITICAL
- "The Procurement Trap": AiTM Phishing-as-a-Service Campaign (EvilProxy, FlowerStorm/Storm-1167, Kali365) Targeting Universities, EU/UN Agencies, and Multinational InstitutionsHIGH
- CodeTracer: Forensic Attribution Tool for Backdoored AI Code-Completion ModelsLOW
- GoldenEyeDog / CylindricalCanine Breaches DigiCert Support System to Hijack EV Code-Signing Certificates for Golden Gh0st RAT and Zhong Stealer DistributionCRITICAL
- SleeperGem: RubyGems Supply Chain Attack via Compromised Dormant Maintainer AccountsHIGH
- Scattered Spider (G1015): RMM-Based Persistence and Social-Engineering Intrusion TradecraftHIGH
- Vidar Infostealer and XMRig Cryptominer Malvertising Campaign Targeting SMBs (Factory-v3 / X3D MINER)MEDIUM
- Phantom Squatting: Attackers Register AI-Hallucinated Domains to Hijack LLM-Guided Traffic (Montana Empire / PhantomRaven)HIGH
- Multiple WolfSSL Critical Vulnerabilities: Certificate Bypass, RCE, and Post-Quantum WeakeningCRITICAL
- Klue Supply Chain Breach: OAuth Token Harvesting & Salesforce CRM Data ExfiltrationCRITICAL
- Miasma Malware Supply Chain Attack Targets npm Packages, Go Module, and GitHub Actions CI/CD PipelinesCRITICAL
- Node.js June 2026 Security Release — 12 Vulnerabilities Across 22.x/24.x/26.x Including Two High-Severity TLS Authentication Bypass and WebCrypto DoS Flaws (CVE-2026-48618, CVE-2026-48933)HIGH
- Mastra npm Supply Chain Attack: 141 @mastra/* Packages Backdoored via easy-day-js Typosquat to Deploy Cross-Platform Infostealer/RATCRITICAL
- Research: ~90% of Leaked Malware Source Code Contains Exploitable Software Weaknesses (Vouvoutsis, Patsakis & Casino, arXiv:2606.05945)
Mitigations
- Architecture and Design, Implementation: Certificates should be carefully managed and checked to assure that data are encrypted with the intended owner's public key.
- Implementation: If certificate pinning is being used, ensure that all relevant properties of the certificate are fully validated before the certificate is pinned, including the hostname.
Source: MITRE CWE, potential mitigations.
Detection methods (MITRE CWE)
- Automated Static Analysis - Binary or Bytecode (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Bytecode Weakness Analysis - including disassembler + source code weakness analysis Binary Weakness Analysis - including disassembler + source code weakness analysis
- Manual Static Analysis - Binary or Bytecode (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Binary / Bytecode disassembler - then use manual analysis for vulnerabilities & anomalies
- Dynamic Analysis with Automated Results Interpretation (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Web Application Scanner
- Dynamic Analysis with Manual Results Interpretation (effectiveness: High): According to SOAR [REF-1479], the following detection techniques may be useful: Highly cost effective: Man-in-the-middle attack tool
- Manual Static Analysis - Source Code (effectiveness: High): According to SOAR [REF-1479], the following detection techniques may be useful: Highly cost effective: Focused Manual Spotcheck - Focused manual analysis of source Manual Source Code Review (not inspections)
- Automated Static Analysis - Source Code (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Source code Weakness Analyzer Context-configured Source Code Weakness Analyzer
- Architecture or Design Review (effectiveness: High): According to SOAR [REF-1479], the following detection techniques may be useful: Highly cost effective: Inspection (IEEE 1028 standard) (can apply to requirements, design, source code, etc.)
Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.