# CWE-321: Use of Hard-coded Cryptographic Key

**Likelihood of exploit:** High · **KEV-linked**

> As of 2026-10-05, CWE-321 (Use of Hard-coded Cryptographic Key) underlies 10 CVEs tracked by Threadlinqs, 2 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 19 tracked threats. MITRE rates its likelihood of exploit as High.

**Last updated:** 2026-10-05

## What is CWE-321?

The product uses a hard-coded, unchangeable cryptographic key.

CWE-321 is a variant-level weakness in MITRE’s Common Weakness Enumeration, with a MITRE likelihood of exploit of High. Applicable platforms: Not Language-Specific; ICS/OT.

_Source: [MITRE CWE](https://cwe.mitre.org/data/definitions/321.html) (CWE-321 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data._

## Consequences

- **Access Control** — Bypass Protection Mechanism, Gain Privileges or Assume Identity, Read Application Data. If hard-coded cryptographic keys are used, it is almost certain that malicious users will gain access through the account in question. The use of a hard-coded cryptographic key significantly increases the possibility that encrypted data may be recovered.

_Source: MITRE CWE, common consequences._

## How CWE-321 is exploited in the wild

Threadlinqs maps 10 CVEs to CWE-321, published between 2016-06-07 and 2026-10-01. 2 are listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild. By CVSS v3 severity the set splits into 5 critical, 1 high, 2 medium. The highest EPSS score in the set is 94.3% (CVE-2025-30406), the modelled probability of exploitation in the next 30 days. 19 tracked threats reference CWE-321 directly or through a CVE it covers; the most recent is “Dell Container Storage Modules (CSM) flaws enable unauthenticated admin access and root on Kubernetes nodes (CVE-2026-63688, CVE-2026-63692, CVE-2026-67269, CVE-2026-54472, CVE-2026-61421, CVE-2026-67273)” (2026-10-02). Affected products concentrate in Apache (1), Digital Knowledge (1), Flowise (1), among 11 vendors in total.

## Vulnerabilities (CVEs)

All 10 CVEs mapped to CWE-321, CISA KEV first, then by CVSS score.

- [CVE-2016-4437](https://intel.threadlinqs.com/cve/CVE-2016-4437) — CISA KEV · CVSS 9.8 critical · EPSS 93.1% · published 2016-06-07
- [CVE-2025-30406](https://intel.threadlinqs.com/cve/CVE-2025-30406) — CISA KEV · CVSS 9 critical · EPSS 94.3% · published 2025-04-03
- [CVE-2026-56271](https://intel.threadlinqs.com/cve/CVE-2026-56271) — CVSS 9.8 critical · EPSS 0.6% · published 2026-07-12
- [CVE-2026-81855](https://intel.threadlinqs.com/cve/CVE-2026-81855) — CVSS 9.1 critical · EPSS 0.4% · published 2026-09-15
- [CVE-2026-5426](https://intel.threadlinqs.com/cve/CVE-2026-5426) — CVSS 9.1 critical · EPSS 0.0% · published 2026-04-16
- [CVE-2026-28326](https://intel.threadlinqs.com/cve/CVE-2026-28326) — CVSS 8.8 high · EPSS 0.6% · published 2026-09-17
- [CVE-2026-84483](https://intel.threadlinqs.com/cve/CVE-2026-84483) — CVSS 5.3 medium · EPSS 0.2% · published 2026-09-01
- [CVE-2025-60250](https://intel.threadlinqs.com/cve/CVE-2025-60250) — CVSS 4.7 medium · EPSS 0.1% · published 2025-09-26
- [CVE-2026-71449](https://intel.threadlinqs.com/cve/CVE-2026-71449) — EPSS 0.2% · published 2026-10-01
- [CVE-2025-30239](https://intel.threadlinqs.com/cve/CVE-2025-30239) — published 2026-08-10

## Affected vendors

- **Apache** — 1 CVE
- **Digital Knowledge** — 1 CVE
- **Flowise** — 1 CVE
- **Gladinet** — 1 CVE
- [Johnson Controls](https://intel.threadlinqs.com/vendors/johnson-controls) — 1 CVE
- **Redhat** — 1 CVE
- [SolarWinds](https://intel.threadlinqs.com/vendors/solarwinds) — 1 CVE
- **TP-Link Systems Inc.** — 1 CVE
- [Unitree](https://intel.threadlinqs.com/vendors/unitree) — 1 CVE
- [WWBN](https://intel.threadlinqs.com/vendors/wwbn) — 1 CVE
- **Wärtsilä** — 1 CVE

## Threat activity

19 tracked threats cite CWE-321:

- [Dell Container Storage Modules (CSM) flaws enable unauthenticated admin access and root on Kubernetes nodes (CVE-2026-63688, CVE-2026-63692, CVE-2026-67269, CVE-2026-54472, CVE-2026-61421, CVE-2026-67273)](https://intel.threadlinqs.com/threat/TL-2026-2851) — CRITICAL · 2026-10-02
- [Chinese-Speaking 'Kapibala' Actor (Red Heron-Linked) Chains WordPress wp2shell, Zyxel GS1900, and Ubiquiti UniFi OS Flaws to Steal Government Data](https://intel.threadlinqs.com/threat/TL-2026-2619) — CRITICAL · 2026-09-22
- [LLM-Driven Reverse Engineering of Palo Alto Cortex XDR Yields Working EDR Evasion (SpecterOps)](https://intel.threadlinqs.com/threat/TL-2026-2576) — HIGH · 2026-09-19
- [SolarWinds Access Rights Manager Hard-Coded Cryptographic Key (CVE-2026-28326) Enables Unauthenticated RCE](https://intel.threadlinqs.com/threat/TL-2026-2585) — CRITICAL · 2026-09-19
- [Team Cymru Infrastructure Analysis: Seven Active Ransomware Gangs (Akira, DragonForce, Clop, MedusaLocker, Qilin, INC Ransom, Lynx) Abuse Dual-Use Tools and Exploit SonicWall, Gladinet CentreStack, and FortiGate Devices](https://intel.threadlinqs.com/threat/TL-2026-2517) — HIGH · 2026-09-15
- [Telerik UI for ASP.NET AJAX — Padding Oracle Chained to Unauthenticated Deserialization RCE (CVE-2026-13181–13184)](https://intel.threadlinqs.com/threat/TL-2026-2369) — HIGH · 2026-09-07
- [Chinese-Speaking Operator "Nie" Uses SecFlow AI Orchestration Framework (Claude, Qwen, DeepSeek) and GLUTTON Steganographic Webshell in Multi-Country Espionage Campaign](https://intel.threadlinqs.com/threat/TL-2026-2325) — HIGH · 2026-09-04
- [Adobe and Nvidia Patch Dozens of Vulnerabilities Across Multiple Products, Including Two Critical Flaws in Nvidia's NemoClaw AI Agent Stack and a CVSS 10.0 Adobe Campaign Classic Chain](https://intel.threadlinqs.com/threat/TL-2026-2152) — CRITICAL · 2026-08-26
- [Adobe Patches Critical RCE Flaws in ColdFusion, Campaign Classic, and Commerce (CVE-2026-48362, CVSS 10.0)](https://intel.threadlinqs.com/threat/TL-2026-1985) — CRITICAL · 2026-08-11
- [Pre-auth RCE chains in Bonita BPM 10.4.3 and Apache OFBiz 24.09.05 (CVE-2026-31986)](https://intel.threadlinqs.com/threat/TL-2026-1898) — CRITICAL · 2026-08-05
- [US FCC Bans Imported Advanced Robots Over Supply-Chain Risk and UniPwn-Class Takeover Vulnerabilities (CVE-2025-35027)](https://intel.threadlinqs.com/threat/TL-2026-1751) — HIGH · 2026-07-29
- [KARR Bluetooth Vulnerability Lets Nearby Attackers Unlock and Immobilize Over 2 Million Cars](https://intel.threadlinqs.com/threat/TL-2026-1699) — HIGH · 2026-07-25
- [KARR Aftermarket Car Alarm Bluetooth Flaw Exposes 2.2M Vehicles to Remote Unlock and Immobilization](https://intel.threadlinqs.com/threat/TL-2026-1701) — HIGH · 2026-07-25
- [TuxBot v3 Evolution: LLM-Assisted IoT Botnet Framework With a Broken Multi-CVE Exploit Chain](https://intel.threadlinqs.com/threat/TL-2026-1366) — HIGH · 2026-07-15
- [StrikeShark Campaign: SharkLoader Dropper Targets Governments and Software Developers via N-Day Exploits and Trojanized Installers to Deploy Cobalt Strike](https://intel.threadlinqs.com/threat/TL-2026-1237) — HIGH · 2026-07-11
- [SharkLoader Malware Campaign Uses Fake Cisco AnyConnect and Google Update Installers to Deploy Cobalt Strike](https://intel.threadlinqs.com/threat/TL-2026-1101) — HIGH · 2026-07-03
- [SharkLoader Malware Deploys Cobalt Strike Beacon via DLL Side-Loading in StrikeShark Campaign](https://intel.threadlinqs.com/threat/TL-2026-0961) — HIGH · 2026-06-27
- [KnowledgeDeliver LMS ViewState Deserialization Zero-Day CVE-2026-5426 — Unauthenticated RCE via Shared ASP.NET machineKey + BLUEBEAM (Godzilla) Web Shell and Cobalt Strike BEACON Watering Hole](https://intel.threadlinqs.com/threat/TL-2026-0577) — CRITICAL · 2026-05-25
- [Iranian IRGC CyberAv3ngers APT Campaign Targeting Rockwell/Allen-Bradley PLCs (CISA AA26-097A)](https://intel.threadlinqs.com/threat/TL-2026-0335) — CRITICAL · 2026-04-08

## Mitigations

- **Architecture and Design**: Prevention schemes mirror that of hard-coded password storage.

_Source: MITRE CWE, potential mitigations._

## Detection methods (MITRE CWE)

- **Automated Static Analysis**: Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)

_Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher._

## Related weaknesses

- [CWE-798 Use of Hard-coded Credentials](https://intel.threadlinqs.com/cwe/CWE-798)

Canonical: https://intel.threadlinqs.com/cwe/CWE-321
Source definition: https://cwe.mitre.org/data/definitions/321.html
Detection rules and IOCs for threats exploiting CWE-321 via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
