# CWE-347: Improper Verification of Cryptographic Signature

**KEV-linked**

> As of 2026-10-05, CWE-347 (Improper Verification of Cryptographic Signature) underlies 24 CVEs tracked by Threadlinqs, 2 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 39 tracked threats.

**Last updated:** 2026-10-05

## What is CWE-347?

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

CWE-347 is a base-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: Not Language-Specific.

_Source: [MITRE CWE](https://cwe.mitre.org/data/definitions/347.html) (CWE-347 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data._

## Consequences

- **Access Control, Integrity, Confidentiality** — Gain Privileges or Assume Identity, Modify Application Data, Execute Unauthorized Code or Commands. An attacker could gain access to sensitive data and possibly execute unauthorized code.

_Source: MITRE CWE, common consequences._

## How CWE-347 is exploited in the wild

Threadlinqs maps 24 CVEs to CWE-347, published between 2025-06-24 and 2026-10-04. 2 are listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild. By CVSS v3 severity the set splits into 9 critical, 6 high, 3 medium. The highest EPSS score in the set is 7.6% (CVE-2025-59718), the modelled probability of exploitation in the next 30 days. 39 tracked threats reference CWE-347 directly or through a CVE it covers; the most recent is “CISA Adds Two Actively Exploited KEVs: SharePoint Code Injection (CVE-2026-65660) and Mikrotik RouterOS Auth Bypass (CVE-2026-67279)” (2026-09-26). Affected products concentrate in CoreWCF (3), wolfSSL (3), Fortinet (2), among 15 vendors in total.

## Vulnerabilities (CVEs)

All 24 CVEs mapped to CWE-347, CISA KEV first, then by CVSS score.

- [CVE-2026-5430](https://intel.threadlinqs.com/cve/CVE-2026-5430) — CISA KEV · CVSS 10 critical · EPSS 0.5% · published 2026-08-06
- [CVE-2025-59718](https://intel.threadlinqs.com/cve/CVE-2025-59718) — CISA KEV · CVSS 9.8 critical · EPSS 7.6% · published 2025-12-09
- [CVE-2026-48558](https://intel.threadlinqs.com/cve/CVE-2026-48558) — CVSS 10 critical · EPSS 0.7% · published 2026-06-12
- [CVE-2026-54782](https://intel.threadlinqs.com/cve/CVE-2026-54782) — CVSS 10 critical · EPSS 0.2% · published 2026-07-08
- [CVE-2026-44748](https://intel.threadlinqs.com/cve/CVE-2026-44748) — CVSS 9.9 critical · EPSS 0.2% · published 2026-06-09
- [CVE-2026-76581](https://intel.threadlinqs.com/cve/CVE-2026-76581) — CVSS 9.8 critical · EPSS 0.3% · published 2026-08-28
- [CVE-2025-59719](https://intel.threadlinqs.com/cve/CVE-2025-59719) — CVSS 9.8 critical · EPSS 0.1% · published 2025-12-09
- [CVE-2025-32977](https://intel.threadlinqs.com/cve/CVE-2025-32977) — CVSS 9.6 critical · EPSS 0.0% · published 2025-06-24
- [CVE-2026-40372](https://intel.threadlinqs.com/cve/CVE-2026-40372) — CVSS 9.1 critical · EPSS 0.0% · published 2026-04-21
- [CVE-2026-7511](https://intel.threadlinqs.com/cve/CVE-2026-7511) — CVSS 7.5 high · EPSS 0.1% · published 2026-06-25
- [CVE-2026-50721](https://intel.threadlinqs.com/cve/CVE-2026-50721) — CVSS 7.5 high · published 2026-07-02
- [CVE-2026-50722](https://intel.threadlinqs.com/cve/CVE-2026-50722) — CVSS 7.5 high · published 2026-07-02
- [CVE-2026-91191](https://intel.threadlinqs.com/cve/CVE-2026-91191) — CVSS 7.5 high · published 2026-09-29
- [CVE-2026-54774](https://intel.threadlinqs.com/cve/CVE-2026-54774) — CVSS 7.4 high · EPSS 0.1% · published 2026-07-08
- [CVE-2026-54783](https://intel.threadlinqs.com/cve/CVE-2026-54783) — CVSS 7.4 high · EPSS 0.1% · published 2026-07-08
- [CVE-2026-6329](https://intel.threadlinqs.com/cve/CVE-2026-6329) — CVSS 6.5 medium · EPSS 0.2% · published 2026-06-25
- [CVE-2026-105161](https://intel.threadlinqs.com/cve/CVE-2026-105161) — CVSS 5.3 medium · published 2026-10-04
- [CVE-2026-105118](https://intel.threadlinqs.com/cve/CVE-2026-105118) — CVSS 4.7 medium · published 2026-10-03
- [CVE-2026-67276](https://intel.threadlinqs.com/cve/CVE-2026-67276) — EPSS 0.2% · published 2026-09-05
- [CVE-2026-57910](https://intel.threadlinqs.com/cve/CVE-2026-57910) — EPSS 0.1% · published 2026-08-25
- [CVE-2026-40941](https://intel.threadlinqs.com/cve/CVE-2026-40941) — EPSS 0.1% · published 2026-06-25
- [CVE-2026-67278](https://intel.threadlinqs.com/cve/CVE-2026-67278) — EPSS 0.1% · published 2026-09-05
- [CVE-2026-86304](https://intel.threadlinqs.com/cve/CVE-2026-86304) — EPSS 0.1% · published 2026-09-06
- [CVE-2026-6331](https://intel.threadlinqs.com/cve/CVE-2026-6331) — EPSS 0.1% · published 2026-06-25

## Affected vendors

- [CoreWCF](https://intel.threadlinqs.com/vendors/corewcf) — 3 CVEs
- [wolfSSL](https://intel.threadlinqs.com/vendors/wolfssl) — 3 CVEs
- [Fortinet](https://intel.threadlinqs.com/vendors/fortinet) — 2 CVEs
- [Mikrotik](https://intel.threadlinqs.com/vendors/mikrotik) — 2 CVEs
- **The Libreswan Project** — 2 CVEs
- [Cacti](https://intel.threadlinqs.com/vendors/cacti) — 1 CVE
- **Lantronix** — 1 CVE
- [Microsoft](https://intel.threadlinqs.com/vendors/microsoft) — 1 CVE
- [OpenIdentityPlatform](https://intel.threadlinqs.com/vendors/openidentityplatform) — 1 CVE
- [SAP_SE](https://intel.threadlinqs.com/vendors/sap-se) — 1 CVE
- **SimpleHelp** — 1 CVE
- **WSO2** — 1 CVE

## Threat activity

39 tracked threats cite CWE-347; the 25 most recent are listed.

- [CISA Adds Two Actively Exploited KEVs: SharePoint Code Injection (CVE-2026-65660) and Mikrotik RouterOS Auth Bypass (CVE-2026-67279)](https://intel.threadlinqs.com/threat/TL-2026-2669) — CRITICAL · 2026-09-26
- [Microsoft Titan Analytics JWT 'alg:none' Authentication Bypass Exposed Access to 17.3 Trillion ClickHouse Rows](https://intel.threadlinqs.com/threat/TL-2026-2675) — HIGH · 2026-09-26
- [CISA Adds Actively Exploited WSO2 API Manager and Adobe Commerce Flaws to KEV Catalog, Warns on SharePoint Code Injection](https://intel.threadlinqs.com/threat/TL-2026-2680) — CRITICAL · 2026-09-25
- [CISA KEV Additions (2026-09-24): WSO2 JWT Authentication Bypass (CVE-2026-5430, CVSS 10.0) and Adobe Commerce/Magento Incorrect Authorization (CVE-2026-71362, CVSS 9.1) Actively Exploited](https://intel.threadlinqs.com/threat/TL-2026-2640) — CRITICAL · 2026-09-24
- [Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM APE1808 Devices (SSA-864900) — Including Actively Exploited FortiCloud SSO Bypass (CVE-2025-59718/-59719) and FortiOS Heap Overflow (CVE-2025-25249)](https://intel.threadlinqs.com/threat/TL-2026-2486) — CRITICAL · 2026-09-13
- [Microsoft September 2026 Patch Tuesday — 999 CVEs, 3 actively exploited zero-days (CVE-2026-85880, CVE-2026-81963, CVE-2026-85046)](https://intel.threadlinqs.com/threat/TL-2026-2407) — CRITICAL · 2026-09-08
- [Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication (MikroTrick)](https://intel.threadlinqs.com/threat/TL-2026-2345) — CRITICAL · 2026-09-06
- [Five Critical WordPress Plugin/Theme Flaws (CVSS up to 10.0) Enable Site Takeover or RCE: WPMU DEV Dashboard, Avada/Fusion Builder, TranslatePress, Pods, GiveWP](https://intel.threadlinqs.com/threat/TL-2026-2210) — CRITICAL · 2026-08-29
- [Critical WatchGuard Agent for Windows Flaws (CVE-2026-57910, CVE-2026-57909) Enable Unauthenticated SYSTEM-Level RCE](https://intel.threadlinqs.com/threat/TL-2026-2162) — CRITICAL · 2026-08-27
- [Edge Infrastructure Under Siege: Tenable and SentinelOne Datasets Reveal Convergent Nation-State and Criminal Exploitation of Perimeter Devices](https://intel.threadlinqs.com/threat/TL-2026-2153) — HIGH · 2026-08-26
- [JarService/Zhima Multi-Stage Android Malware Targets DoFun Automotive Head Units, Linked to BADBOX Botnet](https://intel.threadlinqs.com/threat/TL-2026-2111) — HIGH · 2026-08-22
- [Visa Kernel 3 EMV Protocol Flaw — Zombie Card Relay Attack Enables Expired Contactless Card Purchases](https://intel.threadlinqs.com/threat/TL-2026-2102) — HIGH · 2026-08-21
- [Dragon Breath (APT-Q-27) Deploys RONINGLOADER to Disable Security Tools and Drop Gh0st RAT](https://intel.threadlinqs.com/threat/TL-2026-1996) — HIGH · 2026-08-12
- [CVE-2026-17583 — High-Severity Tampering Flaw in Thermo Fisher Applied Biosystems Forensic DNA Analysis Software](https://intel.threadlinqs.com/threat/TL-2026-1854) — HIGH · 2026-08-04
- [CVE-2026-28323: SolarWinds Web Help Desk SAML Authentication Bypass](https://intel.threadlinqs.com/threat/TL-2026-1789) — CRITICAL · 2026-07-31
- [Vibe-Coded Applications Riddled With Exploitable Security Flaws — Theori Xint.io Study Finds 434 Issues Across AI-Generated Codebases](https://intel.threadlinqs.com/threat/TL-2026-1622) — MEDIUM · 2026-07-22
- [July 2026 Patch Tuesday: Actively Exploited SharePoint RCE (CVE-2026-58644) and AD FS/SharePoint Zero-Days](https://intel.threadlinqs.com/threat/TL-2026-1437) — CRITICAL · 2026-07-17
- [Qilin Ransomware: Custom Rust Loader and Kernel-Level EDR Killer via Weaponized ThrottleStop Driver (CVE-2025-7771)](https://intel.threadlinqs.com/threat/TL-2026-1453) — HIGH · 2026-07-17
- [Forgotten UEFI Shims Undermine Secure Boot (CVE-2026-8863, CVE-2026-10797)](https://intel.threadlinqs.com/threat/TL-2026-1298) — HIGH · 2026-07-14
- [SAP Patches Critical NetWeaver, Approuter, and Commerce Cloud Flaws (CVE-2026-44747, CVE-2026-27690, CVE-2026-44761)](https://intel.threadlinqs.com/threat/TL-2026-1302) — CRITICAL · 2026-07-14
- [11-Year-Old Linux UEFI Shim Bootloader Flaws Enable Secure Boot Bypass (CVE-2026-8863, CVE-2026-10797)](https://intel.threadlinqs.com/threat/TL-2026-1340) — HIGH · 2026-07-14
- [UAT-7810 Expands ORB Networks with LONGLEASH, DOGLEASH, and JARLEASH Malware Suite (CVE-2020-22653, CVE-2020-22658, CVE-2023-25717, CVE-2025-2492)](https://intel.threadlinqs.com/threat/TL-2026-1257) — HIGH · 2026-07-13
- [FortiBleed: Mass Credential Compromise Campaign Against Internet-Exposed Fortinet FortiGate Devices (86,644 Devices, 194 Countries)](https://intel.threadlinqs.com/threat/TL-2026-1232) — CRITICAL · 2026-07-11
- [GodDamn Ransomware (Hyadina) — Third Rebrand from Monster/Beast, Deploys Signed PoisonX Kernel Driver](https://intel.threadlinqs.com/threat/TL-2026-1148) — HIGH · 2026-07-09
- [SimpleHelp Authentication Bypass via Forged OIDC Tokens (CVE-2026-48558) Actively Exploited, Added to CISA KEV](https://intel.threadlinqs.com/threat/TL-2026-1122) — CRITICAL · 2026-07-05

## Detection methods (MITRE CWE)

- **Automated Static Analysis** (effectiveness: High): Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)

_Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher._

## Related weaknesses

- [CWE-345 Insufficient Verification of Data Authenticity](https://intel.threadlinqs.com/cwe/CWE-345)

Canonical: https://intel.threadlinqs.com/cwe/CWE-347
Source definition: https://cwe.mitre.org/data/definitions/347.html
Detection rules and IOCs for threats exploiting CWE-347 via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
