What is CWE-321?
The product uses a hard-coded, unchangeable cryptographic key.
CWE-321 is a variant-level weakness in MITRE’s Common Weakness Enumeration, with a MITRE likelihood of exploit of High. Applicable platforms: Not Language-Specific; ICS/OT.
Source: MITRE CWE (CWE-321 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.
Consequences
- Access Control — Bypass Protection Mechanism, Gain Privileges or Assume Identity, Read Application Data. If hard-coded cryptographic keys are used, it is almost certain that malicious users will gain access through the account in question. The use of a hard-coded cryptographic key significantly increases the possibility that encrypted data may be recovered.
Source: MITRE CWE, common consequences.
How CWE-321 is exploited in the wild
Threadlinqs maps 10 CVEs to CWE-321, published between 2016-06-07 and 2026-10-01. 2 are listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild. By CVSS v3 severity the set splits into 5 critical, 1 high, 2 medium. The highest EPSS score in the set is 94.3% (CVE-2025-30406), the modelled probability of exploitation in the next 30 days. 19 tracked threats reference CWE-321 directly or through a CVE it covers; the most recent is “Dell Container Storage Modules (CSM) flaws enable unauthenticated admin access and root on Kubernetes nodes (CVE-2026-63688, CVE-2026-63692, CVE-2026-67269, CVE-2026-54472, CVE-2026-61421, CVE-2026-67273)” (2026-10-02). Affected products concentrate in Apache (1), Digital Knowledge (1), Flowise (1), among 11 vendors in total.
Vulnerabilities (CVEs)
All 10 CVEs mapped to CWE-321, CISA KEV first, then by CVSS score.
- CVE-2016-4437 — CISA KEV · CVSS 9.8 critical · EPSS 93.1% · published 2016-06-07
- CVE-2025-30406 — CISA KEV · CVSS 9 critical · EPSS 94.3% · published 2025-04-03
- CVE-2026-56271 — CVSS 9.8 critical · EPSS 0.6% · published 2026-07-12
- CVE-2026-81855 — CVSS 9.1 critical · EPSS 0.4% · published 2026-09-15
- CVE-2026-5426 — CVSS 9.1 critical · EPSS 0.0% · published 2026-04-16
- CVE-2026-28326 — CVSS 8.8 high · EPSS 0.6% · published 2026-09-17
- CVE-2026-84483 — CVSS 5.3 medium · EPSS 0.2% · published 2026-09-01
- CVE-2025-60250 — CVSS 4.7 medium · EPSS 0.1% · published 2025-09-26
- CVE-2026-71449 — EPSS 0.2% · published 2026-10-01
- CVE-2025-30239 — published 2026-08-10
Affected vendors
- Apache — 1 CVE
- Digital Knowledge — 1 CVE
- Flowise — 1 CVE
- Gladinet — 1 CVE
- Johnson Controls — 1 CVE
- Redhat — 1 CVE
- SolarWinds — 1 CVE
- TP-Link Systems Inc. — 1 CVE
- Unitree — 1 CVE
- WWBN — 1 CVE
- Wärtsilä — 1 CVE
Threat activity
19 tracked threats cite CWE-321:
- Dell Container Storage Modules (CSM) flaws enable unauthenticated admin access and root on Kubernetes nodes (CVE-2026-63688, CVE-2026-63692, CVE-2026-67269, CVE-2026-54472, CVE-2026-61421, CVE-2026-67273)CRITICAL
- Chinese-Speaking 'Kapibala' Actor (Red Heron-Linked) Chains WordPress wp2shell, Zyxel GS1900, and Ubiquiti UniFi OS Flaws to Steal Government DataCRITICAL
- LLM-Driven Reverse Engineering of Palo Alto Cortex XDR Yields Working EDR Evasion (SpecterOps)HIGH
- SolarWinds Access Rights Manager Hard-Coded Cryptographic Key (CVE-2026-28326) Enables Unauthenticated RCECRITICAL
- Team Cymru Infrastructure Analysis: Seven Active Ransomware Gangs (Akira, DragonForce, Clop, MedusaLocker, Qilin, INC Ransom, Lynx) Abuse Dual-Use Tools and Exploit SonicWall, Gladinet CentreStack, and FortiGate DevicesHIGH
- Telerik UI for ASP.NET AJAX — Padding Oracle Chained to Unauthenticated Deserialization RCE (CVE-2026-13181–13184)HIGH
- Chinese-Speaking Operator "Nie" Uses SecFlow AI Orchestration Framework (Claude, Qwen, DeepSeek) and GLUTTON Steganographic Webshell in Multi-Country Espionage CampaignHIGH
- Adobe and Nvidia Patch Dozens of Vulnerabilities Across Multiple Products, Including Two Critical Flaws in Nvidia's NemoClaw AI Agent Stack and a CVSS 10.0 Adobe Campaign Classic ChainCRITICAL
- Adobe Patches Critical RCE Flaws in ColdFusion, Campaign Classic, and Commerce (CVE-2026-48362, CVSS 10.0)CRITICAL
- Pre-auth RCE chains in Bonita BPM 10.4.3 and Apache OFBiz 24.09.05 (CVE-2026-31986)CRITICAL
- US FCC Bans Imported Advanced Robots Over Supply-Chain Risk and UniPwn-Class Takeover Vulnerabilities (CVE-2025-35027)HIGH
- KARR Bluetooth Vulnerability Lets Nearby Attackers Unlock and Immobilize Over 2 Million CarsHIGH
- KARR Aftermarket Car Alarm Bluetooth Flaw Exposes 2.2M Vehicles to Remote Unlock and ImmobilizationHIGH
- TuxBot v3 Evolution: LLM-Assisted IoT Botnet Framework With a Broken Multi-CVE Exploit ChainHIGH
- StrikeShark Campaign: SharkLoader Dropper Targets Governments and Software Developers via N-Day Exploits and Trojanized Installers to Deploy Cobalt StrikeHIGH
- SharkLoader Malware Campaign Uses Fake Cisco AnyConnect and Google Update Installers to Deploy Cobalt StrikeHIGH
- SharkLoader Malware Deploys Cobalt Strike Beacon via DLL Side-Loading in StrikeShark CampaignHIGH
- KnowledgeDeliver LMS ViewState Deserialization Zero-Day CVE-2026-5426 — Unauthenticated RCE via Shared ASP.NET machineKey + BLUEBEAM (Godzilla) Web Shell and Cobalt Strike BEACON Watering HoleCRITICAL
- Iranian IRGC CyberAv3ngers APT Campaign Targeting Rockwell/Allen-Bradley PLCs (CISA AA26-097A)CRITICAL
Mitigations
- Architecture and Design: Prevention schemes mirror that of hard-coded password storage.
Source: MITRE CWE, potential mitigations.
Detection methods (MITRE CWE)
- Automated Static Analysis: Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)
Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.