Threadlinqs IntelligenceStart free

Weakness · BaseCWE-347

CWE-347: Improper Verification of Cryptographic Signature

KEV-linkedBase

As of 2026-10-05, CWE-347 (Improper Verification of Cryptographic Signature) underlies 24 CVEs tracked by Threadlinqs, 2 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 39 tracked threats.

CVEs
24Mapped to CWE-347
CISA KEV
2Exploited in the wild
Critical
9CVSS v3 critical CVEs
Threats
39Tracked campaigns citing it
Likelihood
—MITRE likelihood of exploit

Last updated:

What is CWE-347?

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

CWE-347 is a base-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: Not Language-Specific.

Source: MITRE CWE (CWE-347 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.

Consequences

  • Access Control, Integrity, Confidentiality — Gain Privileges or Assume Identity, Modify Application Data, Execute Unauthorized Code or Commands. An attacker could gain access to sensitive data and possibly execute unauthorized code.

Source: MITRE CWE, common consequences.

How CWE-347 is exploited in the wild

Threadlinqs maps 24 CVEs to CWE-347, published between 2025-06-24 and 2026-10-04. 2 are listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild. By CVSS v3 severity the set splits into 9 critical, 6 high, 3 medium. The highest EPSS score in the set is 7.6% (CVE-2025-59718), the modelled probability of exploitation in the next 30 days. 39 tracked threats reference CWE-347 directly or through a CVE it covers; the most recent is “CISA Adds Two Actively Exploited KEVs: SharePoint Code Injection (CVE-2026-65660) and Mikrotik RouterOS Auth Bypass (CVE-2026-67279)” (2026-09-26). Affected products concentrate in CoreWCF (3), wolfSSL (3), Fortinet (2), among 15 vendors in total.

Vulnerabilities (CVEs)

All 24 CVEs mapped to CWE-347, CISA KEV first, then by CVSS score.

Affected vendors

Threat activity

39 tracked threats cite CWE-347; the 25 most recent are listed.

Detection methods (MITRE CWE)

  • Automated Static Analysis (effectiveness: High): Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)

Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.