What is CWE-347?
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
CWE-347 is a base-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: Not Language-Specific.
Source: MITRE CWE (CWE-347 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.
Consequences
- Access Control, Integrity, Confidentiality — Gain Privileges or Assume Identity, Modify Application Data, Execute Unauthorized Code or Commands. An attacker could gain access to sensitive data and possibly execute unauthorized code.
Source: MITRE CWE, common consequences.
How CWE-347 is exploited in the wild
Threadlinqs maps 24 CVEs to CWE-347, published between 2025-06-24 and 2026-10-04. 2 are listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild. By CVSS v3 severity the set splits into 9 critical, 6 high, 3 medium. The highest EPSS score in the set is 7.6% (CVE-2025-59718), the modelled probability of exploitation in the next 30 days. 39 tracked threats reference CWE-347 directly or through a CVE it covers; the most recent is “CISA Adds Two Actively Exploited KEVs: SharePoint Code Injection (CVE-2026-65660) and Mikrotik RouterOS Auth Bypass (CVE-2026-67279)” (2026-09-26). Affected products concentrate in CoreWCF (3), wolfSSL (3), Fortinet (2), among 15 vendors in total.
Vulnerabilities (CVEs)
All 24 CVEs mapped to CWE-347, CISA KEV first, then by CVSS score.
- CVE-2026-5430 — CISA KEV · CVSS 10 critical · EPSS 0.5% · published 2026-08-06
- CVE-2025-59718 — CISA KEV · CVSS 9.8 critical · EPSS 7.6% · published 2025-12-09
- CVE-2026-48558 — CVSS 10 critical · EPSS 0.7% · published 2026-06-12
- CVE-2026-54782 — CVSS 10 critical · EPSS 0.2% · published 2026-07-08
- CVE-2026-44748 — CVSS 9.9 critical · EPSS 0.2% · published 2026-06-09
- CVE-2026-76581 — CVSS 9.8 critical · EPSS 0.3% · published 2026-08-28
- CVE-2025-59719 — CVSS 9.8 critical · EPSS 0.1% · published 2025-12-09
- CVE-2025-32977 — CVSS 9.6 critical · EPSS 0.0% · published 2025-06-24
- CVE-2026-40372 — CVSS 9.1 critical · EPSS 0.0% · published 2026-04-21
- CVE-2026-7511 — CVSS 7.5 high · EPSS 0.1% · published 2026-06-25
- CVE-2026-50721 — CVSS 7.5 high · published 2026-07-02
- CVE-2026-50722 — CVSS 7.5 high · published 2026-07-02
- CVE-2026-91191 — CVSS 7.5 high · published 2026-09-29
- CVE-2026-54774 — CVSS 7.4 high · EPSS 0.1% · published 2026-07-08
- CVE-2026-54783 — CVSS 7.4 high · EPSS 0.1% · published 2026-07-08
- CVE-2026-6329 — CVSS 6.5 medium · EPSS 0.2% · published 2026-06-25
- CVE-2026-105161 — CVSS 5.3 medium · published 2026-10-04
- CVE-2026-105118 — CVSS 4.7 medium · published 2026-10-03
- CVE-2026-67276 — EPSS 0.2% · published 2026-09-05
- CVE-2026-57910 — EPSS 0.1% · published 2026-08-25
- CVE-2026-40941 — EPSS 0.1% · published 2026-06-25
- CVE-2026-67278 — EPSS 0.1% · published 2026-09-05
- CVE-2026-86304 — EPSS 0.1% · published 2026-09-06
- CVE-2026-6331 — EPSS 0.1% · published 2026-06-25
Affected vendors
Threat activity
39 tracked threats cite CWE-347; the 25 most recent are listed.
- CISA Adds Two Actively Exploited KEVs: SharePoint Code Injection (CVE-2026-65660) and Mikrotik RouterOS Auth Bypass (CVE-2026-67279)CRITICAL
- Microsoft Titan Analytics JWT 'alg:none' Authentication Bypass Exposed Access to 17.3 Trillion ClickHouse RowsHIGH
- CISA Adds Actively Exploited WSO2 API Manager and Adobe Commerce Flaws to KEV Catalog, Warns on SharePoint Code InjectionCRITICAL
- CISA KEV Additions (2026-09-24): WSO2 JWT Authentication Bypass (CVE-2026-5430, CVSS 10.0) and Adobe Commerce/Magento Incorrect Authorization (CVE-2026-71362, CVSS 9.1) Actively ExploitedCRITICAL
- Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM APE1808 Devices (SSA-864900) — Including Actively Exploited FortiCloud SSO Bypass (CVE-2025-59718/-59719) and FortiOS Heap Overflow (CVE-2025-25249)CRITICAL
- Microsoft September 2026 Patch Tuesday — 999 CVEs, 3 actively exploited zero-days (CVE-2026-85880, CVE-2026-81963, CVE-2026-85046)CRITICAL
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication (MikroTrick)CRITICAL
- Five Critical WordPress Plugin/Theme Flaws (CVSS up to 10.0) Enable Site Takeover or RCE: WPMU DEV Dashboard, Avada/Fusion Builder, TranslatePress, Pods, GiveWPCRITICAL
- Critical WatchGuard Agent for Windows Flaws (CVE-2026-57910, CVE-2026-57909) Enable Unauthenticated SYSTEM-Level RCECRITICAL
- Edge Infrastructure Under Siege: Tenable and SentinelOne Datasets Reveal Convergent Nation-State and Criminal Exploitation of Perimeter DevicesHIGH
- JarService/Zhima Multi-Stage Android Malware Targets DoFun Automotive Head Units, Linked to BADBOX BotnetHIGH
- Visa Kernel 3 EMV Protocol Flaw — Zombie Card Relay Attack Enables Expired Contactless Card PurchasesHIGH
- Dragon Breath (APT-Q-27) Deploys RONINGLOADER to Disable Security Tools and Drop Gh0st RATHIGH
- CVE-2026-17583 — High-Severity Tampering Flaw in Thermo Fisher Applied Biosystems Forensic DNA Analysis SoftwareHIGH
- CVE-2026-28323: SolarWinds Web Help Desk SAML Authentication BypassCRITICAL
- Vibe-Coded Applications Riddled With Exploitable Security Flaws — Theori Xint.io Study Finds 434 Issues Across AI-Generated CodebasesMEDIUM
- July 2026 Patch Tuesday: Actively Exploited SharePoint RCE (CVE-2026-58644) and AD FS/SharePoint Zero-DaysCRITICAL
- Qilin Ransomware: Custom Rust Loader and Kernel-Level EDR Killer via Weaponized ThrottleStop Driver (CVE-2025-7771)HIGH
- Forgotten UEFI Shims Undermine Secure Boot (CVE-2026-8863, CVE-2026-10797)HIGH
- SAP Patches Critical NetWeaver, Approuter, and Commerce Cloud Flaws (CVE-2026-44747, CVE-2026-27690, CVE-2026-44761)CRITICAL
- 11-Year-Old Linux UEFI Shim Bootloader Flaws Enable Secure Boot Bypass (CVE-2026-8863, CVE-2026-10797)HIGH
- UAT-7810 Expands ORB Networks with LONGLEASH, DOGLEASH, and JARLEASH Malware Suite (CVE-2020-22653, CVE-2020-22658, CVE-2023-25717, CVE-2025-2492)HIGH
- FortiBleed: Mass Credential Compromise Campaign Against Internet-Exposed Fortinet FortiGate Devices (86,644 Devices, 194 Countries)CRITICAL
- GodDamn Ransomware (Hyadina) — Third Rebrand from Monster/Beast, Deploys Signed PoisonX Kernel DriverHIGH
- SimpleHelp Authentication Bypass via Forged OIDC Tokens (CVE-2026-48558) Actively Exploited, Added to CISA KEVCRITICAL
Detection methods (MITRE CWE)
- Automated Static Analysis (effectiveness: High): Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)
Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.