# CWE-295: Improper Certificate Validation

**KEV-linked**

> As of 2026-10-05, CWE-295 (Improper Certificate Validation) underlies 15 CVEs tracked by Threadlinqs, 2 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 34 tracked threats.

**Last updated:** 2026-10-05

## What is CWE-295?

The product does not validate, or incorrectly validates, a certificate.

CWE-295 is a base-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: Not Language-Specific; Technology: Not Technology-Specific; Technology: Web Based; Technology: Mobile.

_Source: [MITRE CWE](https://cwe.mitre.org/data/definitions/295.html) (CWE-295 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data._

## Consequences

- **Integrity, Authentication** — Bypass Protection Mechanism, Gain Privileges or Assume Identity. When a certificate is invalid or malicious, it might allow an attacker to spoof a trusted entity by interfering in the communication path between the host and client. The product might connect to a malicious host while believing it is a trusted host, or the product might be deceived into accepting spoofed data that appears to originate from a trusted host.

_Source: MITRE CWE, common consequences._

## How CWE-295 is exploited in the wild

Threadlinqs maps 15 CVEs to CWE-295, published between 2022-05-10 and 2026-10-04. 2 are listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild, and 1 is tied to ransomware campaigns. By CVSS v3 severity the set splits into 2 critical, 7 high, 1 medium, 2 low. The highest EPSS score in the set is 91.5% (CVE-2022-26923), the modelled probability of exploitation in the next 30 days. 34 tracked threats reference CWE-295 directly or through a CVE it covers; the most recent is “WatchGuard Fireware OS Critical Code Injection Vulnerability in BOVPN over TLS Client (CVE-2026-86131)” (2026-09-30). Affected products concentrate in Apple (1), Cisco (1), IBM (1), among 15 vendors in total.

## Vulnerabilities (CVEs)

All 15 CVEs mapped to CWE-295, CISA KEV first, then by CVSS score.

- [CVE-2022-26923](https://intel.threadlinqs.com/cve/CVE-2022-26923) — CISA KEV · CVSS 8.8 high · EPSS 91.5% · published 2022-05-10
- [CVE-2023-41991](https://intel.threadlinqs.com/cve/CVE-2023-41991) — CISA KEV · CVSS 5.5 medium · EPSS 3.2% · published 2023-09-21
- [CVE-2026-85102](https://intel.threadlinqs.com/cve/CVE-2026-85102) — CVSS 9.8 critical · EPSS 0.3% · published 2026-09-09
- [CVE-2026-20184](https://intel.threadlinqs.com/cve/CVE-2026-20184) — CVSS 9.8 critical · EPSS 0.0% · published 2026-04-15
- [CVE-2026-105216](https://intel.threadlinqs.com/cve/CVE-2026-105216) — CVSS 7.4 high · published 2026-10-04
- [CVE-2026-105218](https://intel.threadlinqs.com/cve/CVE-2026-105218) — CVSS 7.4 high · published 2026-10-04
- [CVE-2026-105221](https://intel.threadlinqs.com/cve/CVE-2026-105221) — CVSS 7.4 high · published 2026-10-04
- [CVE-2026-105222](https://intel.threadlinqs.com/cve/CVE-2026-105222) — CVSS 7.4 high · published 2026-10-04
- [CVE-2026-56820](https://intel.threadlinqs.com/cve/CVE-2026-56820) — CVSS 7.4 high · published 2026-07-21
- [CVE-2026-90647](https://intel.threadlinqs.com/cve/CVE-2026-90647) — CVSS 7.4 high · published 2026-09-12
- [CVE-2026-18173](https://intel.threadlinqs.com/cve/CVE-2026-18173) — CVSS 3.7 low · EPSS 0.2% · published 2026-09-22
- [CVE-2026-105217](https://intel.threadlinqs.com/cve/CVE-2026-105217) — CVSS 3.1 low · published 2026-10-04
- [CVE-2026-86131](https://intel.threadlinqs.com/cve/CVE-2026-86131) — EPSS 0.3% · published 2026-09-29
- [CVE-2026-7532](https://intel.threadlinqs.com/cve/CVE-2026-7532) — EPSS 0.0% · published 2026-06-25
- [CVE-2026-69248](https://intel.threadlinqs.com/cve/CVE-2026-69248) — published 2026-08-03

## Affected vendors

- [Apple](https://intel.threadlinqs.com/vendors/apple) — 1 CVE
- [Cisco](https://intel.threadlinqs.com/vendors/cisco) — 1 CVE
- [IBM](https://intel.threadlinqs.com/vendors/ibm) — 1 CVE
- **Kalkitech** — 1 CVE
- [Microsoft](https://intel.threadlinqs.com/vendors/microsoft) — 1 CVE
- [WatchGuard](https://intel.threadlinqs.com/vendors/watchguard) — 1 CVE
- **alexpechkarev** — 1 CVE
- [checkpoint](https://intel.threadlinqs.com/vendors/checkpoint) — 1 CVE
- **cockpit-hq** — 1 CVE
- **defunkt** — 1 CVE
- **go-pay** — 1 CVE
- **micro** — 1 CVE

## Threat activity

34 tracked threats cite CWE-295; the 25 most recent are listed.

- [WatchGuard Fireware OS Critical Code Injection Vulnerability in BOVPN over TLS Client (CVE-2026-86131)](https://intel.threadlinqs.com/threat/TL-2026-2813) — CRITICAL · 2026-09-30
- [Check Point Security Gateway VPN Pre-Auth RCE (CVE-2026-85102) and Management Path Traversal Zero-Day (CVE-2026-93616) Actively Exploited](https://intel.threadlinqs.com/threat/TL-2026-2677) — CRITICAL · 2026-09-26
- [CISA Adds Four Actively Exploited KEVs: Check Point Gateway/Management RCE Flaws, Arista VeloCloud Orchestrator Auth Bypass, F5 BIG-IP APM Heap Overflow](https://intel.threadlinqs.com/threat/TL-2026-2678) — CRITICAL · 2026-09-26
- [Eclypsium InfraTrust Report: Mass Active Exploitation of Network Management Systems (Cisco FMC/ISE CVE-2026-20079, CVE-2026-76460; SonicWall SMA 1000 CVE-2026-83548/83549; Linux Kernel CopyFail CVE-2026-31431)](https://intel.threadlinqs.com/threat/TL-2026-2630) — CRITICAL · 2026-09-23
- [SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems Drop a Persistent Backdoor](https://intel.threadlinqs.com/threat/TL-2026-2497) — CRITICAL · 2026-09-14
- [Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM APE1808 Devices (SSA-864900) — Including Actively Exploited FortiCloud SSO Bypass (CVE-2025-59718/-59719) and FortiOS Heap Overflow (CVE-2025-25249)](https://intel.threadlinqs.com/threat/TL-2026-2486) — CRITICAL · 2026-09-13
- [Dutch NCSC Warns of Critical Check Point VPN Flaws (CVE-2026-85102, CVE-2026-85103) — Exploitation Expected Imminently](https://intel.threadlinqs.com/threat/TL-2026-2463) — CRITICAL · 2026-09-12
- [Adobe and Nvidia Patch Dozens of Vulnerabilities Across Multiple Products, Including Two Critical Flaws in Nvidia's NemoClaw AI Agent Stack and a CVSS 10.0 Adobe Campaign Classic Chain](https://intel.threadlinqs.com/threat/TL-2026-2152) — CRITICAL · 2026-08-26
- [FirewallFalcon Manager: Supply-Chain Backdoor in Underground VPN Server Infrastructure](https://intel.threadlinqs.com/threat/TL-2026-1947) — CRITICAL · 2026-08-07
- [Node.js Patches 11 Security Flaws Across v22.23.2, v24.18.1, v26.5.1 (HTTP/2 DoS, Permission Model Bypass, TLS/mTLS Issues)](https://intel.threadlinqs.com/threat/TL-2026-1807) — HIGH · 2026-08-01
- [SleeperGem: RubyGems Supply Chain Attack Uses Hijacked Dormant Maintainer Accounts to Weaponize git_credential_manager, Dendreo, and fastlane-plugin-run_tests_firebase_testlab](https://intel.threadlinqs.com/threat/TL-2026-1703) — HIGH · 2026-07-26
- [Critical ASUS Router Flaw (CVE-2026-13385) Enables MITM Arbitrary Command Execution](https://intel.threadlinqs.com/threat/TL-2026-1617) — CRITICAL · 2026-07-22
- ["The Procurement Trap": AiTM Phishing-as-a-Service Campaign (EvilProxy, FlowerStorm/Storm-1167, Kali365) Targeting Universities, EU/UN Agencies, and Multinational Institutions](https://intel.threadlinqs.com/threat/TL-2026-1593) — HIGH · 2026-07-21
- [CodeTracer: Forensic Attribution Tool for Backdoored AI Code-Completion Models](https://intel.threadlinqs.com/threat/TL-2026-1577) — LOW · 2026-07-20
- [GoldenEyeDog / CylindricalCanine Breaches DigiCert Support System to Hijack EV Code-Signing Certificates for Golden Gh0st RAT and Zhong Stealer Distribution](https://intel.threadlinqs.com/threat/TL-2026-1579) — CRITICAL · 2026-07-20
- [SleeperGem: RubyGems Supply Chain Attack via Compromised Dormant Maintainer Accounts](https://intel.threadlinqs.com/threat/TL-2026-1514) — HIGH · 2026-07-19
- [Scattered Spider (G1015): RMM-Based Persistence and Social-Engineering Intrusion Tradecraft](https://intel.threadlinqs.com/threat/TL-2026-1333) — HIGH · 2026-07-14
- [Vidar Infostealer and XMRig Cryptominer Malvertising Campaign Targeting SMBs (Factory-v3 / X3D MINER)](https://intel.threadlinqs.com/threat/TL-2026-1183) — MEDIUM · 2026-07-10
- [Phantom Squatting: Attackers Register AI-Hallucinated Domains to Hijack LLM-Guided Traffic (Montana Empire / PhantomRaven)](https://intel.threadlinqs.com/threat/TL-2026-1031) — HIGH · 2026-07-01
- [Multiple WolfSSL Critical Vulnerabilities: Certificate Bypass, RCE, and Post-Quantum Weakening](https://intel.threadlinqs.com/threat/TL-2026-1008) — CRITICAL · 2026-06-30
- [Klue Supply Chain Breach: OAuth Token Harvesting & Salesforce CRM Data Exfiltration](https://intel.threadlinqs.com/threat/TL-2026-0976) — CRITICAL · 2026-06-28
- [Miasma Malware Supply Chain Attack Targets npm Packages, Go Module, and GitHub Actions CI/CD Pipelines](https://intel.threadlinqs.com/threat/TL-2026-0963) — CRITICAL · 2026-06-27
- [Node.js June 2026 Security Release — 12 Vulnerabilities Across 22.x/24.x/26.x Including Two High-Severity TLS Authentication Bypass and WebCrypto DoS Flaws (CVE-2026-48618, CVE-2026-48933)](https://intel.threadlinqs.com/threat/TL-2026-0866) — HIGH · 2026-06-19
- [Mastra npm Supply Chain Attack: 141 @mastra/* Packages Backdoored via easy-day-js Typosquat to Deploy Cross-Platform Infostealer/RAT](https://intel.threadlinqs.com/threat/TL-2026-0836) — CRITICAL · 2026-06-17
- [Research: ~90% of Leaked Malware Source Code Contains Exploitable Software Weaknesses (Vouvoutsis, Patsakis & Casino, arXiv:2606.05945)](https://intel.threadlinqs.com/threat/TL-2026-0739) — INFO · 2026-06-09

## Mitigations

- **Architecture and Design, Implementation**: Certificates should be carefully managed and checked to assure that data are encrypted with the intended owner's public key.
- **Implementation**: If certificate pinning is being used, ensure that all relevant properties of the certificate are fully validated before the certificate is pinned, including the hostname.

_Source: MITRE CWE, potential mitigations._

## Detection methods (MITRE CWE)

- **Automated Static Analysis - Binary or Bytecode** (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Bytecode Weakness Analysis - including disassembler + source code weakness analysis Binary Weakness Analysis - including disassembler + source code weakness analysis
- **Manual Static Analysis - Binary or Bytecode** (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Binary / Bytecode disassembler - then use manual analysis for vulnerabilities & anomalies
- **Dynamic Analysis with Automated Results Interpretation** (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Web Application Scanner
- **Dynamic Analysis with Manual Results Interpretation** (effectiveness: High): According to SOAR [REF-1479], the following detection techniques may be useful: Highly cost effective: Man-in-the-middle attack tool
- **Manual Static Analysis - Source Code** (effectiveness: High): According to SOAR [REF-1479], the following detection techniques may be useful: Highly cost effective: Focused Manual Spotcheck - Focused manual analysis of source Manual Source Code Review (not inspections)
- **Automated Static Analysis - Source Code** (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Source code Weakness Analyzer Context-configured Source Code Weakness Analyzer
- **Architecture or Design Review** (effectiveness: High): According to SOAR [REF-1479], the following detection techniques may be useful: Highly cost effective: Inspection (IEEE 1028 standard) (can apply to requirements, design, source code, etc.)

_Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher._

## Related weaknesses

- [CWE-287 Improper Authentication](https://intel.threadlinqs.com/cwe/CWE-287)
- [CWE-322](https://cwe.mitre.org/data/definitions/322.html)

Canonical: https://intel.threadlinqs.com/cwe/CWE-295
Source definition: https://cwe.mitre.org/data/definitions/295.html
Detection rules and IOCs for threats exploiting CWE-295 via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
