Threadlinqs IntelligenceStart free

Weakness · VariantCWE-416

CWE-416: Use After Free

Likelihood of exploit: HighKEV-linkedVariant

As of 2026-10-05, CWE-416 (Use After Free) underlies 95 CVEs tracked by Threadlinqs, 18 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 92 tracked threats. MITRE rates its likelihood of exploit as High.

CVEs
95Mapped to CWE-416
CISA KEV
18Exploited in the wild
Critical
18CVSS v3 critical CVEs
Threats
92Tracked campaigns citing it
Likelihood
HighMITRE likelihood of exploit

Last updated:

What is CWE-416?

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

CWE-416 is a variant-level weakness in MITRE’s Common Weakness Enumeration, with a MITRE likelihood of exploit of High. Applicable platforms: Language: Memory-Unsafe; Language: C; Language: C++.

Source: MITRE CWE (CWE-416 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.

Consequences

  • Integrity — Modify Memory. The use of previously freed memory may corrupt valid data, if the memory area in question has been allocated and used properly elsewhere.
  • Availability — DoS: Crash, Exit, or Restart. If chunk consolidation occurs after the use of previously freed data, the process may crash when invalid data is used as chunk information.
  • Integrity, Confidentiality, Availability — Execute Unauthorized Code or Commands. If malicious data is entered before chunk consolidation can take place, it may be possible to take advantage of a write-what-where primitive to execute arbitrary code. If the newly allocated data happens to hold a class, in C++ for example, various function pointers may be scattered within the heap data. If one of these function pointers is overwritten with an address to valid shellcode, execution of arbitrary code can be achieved.

Source: MITRE CWE, common consequences.

How CWE-416 is exploited in the wild

Threadlinqs maps 95 CVEs to CWE-416, published between 2010-01-15 and 2026-09-29. 18 are listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild, and 4 are tied to ransomware campaigns. By CVSS v3 severity the set splits into 18 critical, 61 high, 7 medium, 2 low. The highest EPSS score in the set is 99.9% (CVE-2019-0708), the modelled probability of exploitation in the next 30 days. 92 tracked threats reference CWE-416 directly or through a CVE it covers; the most recent is “Multiple Vulnerabilities in Microsoft Edge prior to 154.0.4258.53 (HK GovCERT A26-10-03)” (2026-10-02). Affected products concentrate in Google (41), Microsoft (27), Apple (8), among 31 vendors in total.

Vulnerabilities (CVEs)

Showing 40 of 95 CVEs mapped to CWE-416, CISA KEV first, then by CVSS score.

  • CVE-2019-0708 — CISA KEV · CVSS 9.8 critical · EPSS 99.9% · published 2019-05-16
  • CVE-2024-9680 — CISA KEV · CVSS 9.8 critical · EPSS 30.8% · published 2024-10-09
  • CVE-2026-34621 — CISA KEV · CVSS 9.8 critical · EPSS 9.8% · published 2026-04-13
  • CVE-2021-37973 — CISA KEV · CVSS 9.6 critical · EPSS 6.4% · published 2021-10-08
  • CVE-2010-0249 — CISA KEV · CVSS 8.8 high · EPSS 88.7% · published 2010-01-15
  • CVE-2010-0806 — CISA KEV · CVSS 8.8 high · EPSS 87.2% · published 2010-03-10
  • CVE-2026-5281 — CISA KEV · CVSS 8.8 high · EPSS 3.2% · published 2026-04-01
  • CVE-2026-2441 — CISA KEV · CVSS 8.8 high · EPSS 0.2% · published 2026-02-13
  • CVE-2025-43529 — CISA KEV · CVSS 8.8 high · EPSS 0.1% · published 2025-12-17
  • CVE-2023-43000 — CISA KEV · CVSS 8.8 high · EPSS 0.0% · published 2025-11-05
  • CVE-2023-32373 — CISA KEV · CVSS 8.8 high · EPSS 0.0% · published 2023-06-23
  • CVE-2021-1048 — CISA KEV · CVSS 7.8 high · EPSS 1.2% · published 2021-12-15
  • CVE-2024-43047 — CISA KEV · CVSS 7.8 high · EPSS 0.6% · published 2024-10-07
  • CVE-2024-4610 — CISA KEV · CVSS 7.8 high · EPSS 0.5% · published 2024-06-07
  • CVE-2023-41974 — CISA KEV · CVSS 7.8 high · EPSS 0.1% · published 2024-01-10
  • CVE-2025-48543 — CISA KEV · CVSS 7.5 high · EPSS 0.3% · published 2025-09-04
  • CVE-2026-68820 — CISA KEV · CVSS 7 high · EPSS 0.3% · published 2026-08-11
  • CVE-2022-2586 — CISA KEV · CVSS 5.3 medium · EPSS 10.4% · published 2024-01-08
  • CVE-2025-49844 — CVSS 10 critical · EPSS 11.1% · published 2025-10-03
  • CVE-2026-57092 — CVSS 9.9 critical · published 2026-07-14
  • CVE-2020-28951 — CVSS 9.8 critical · EPSS 1.7% · published 2020-11-19
  • CVE-2026-69525 — CVSS 9.8 critical · EPSS 0.9% · published 2026-09-08
  • CVE-2026-69730 — CVSS 9.8 critical · EPSS 0.9% · published 2026-09-08
  • CVE-2026-81934 — CVSS 9.8 critical · EPSS 0.5% · published 2026-08-27
  • CVE-2026-45185 — CVSS 9.8 critical · EPSS 0.0% · published 2026-05-12
  • CVE-2026-87464 — CVSS 9.6 critical · EPSS 0.5% · published 2026-09-09
  • CVE-2026-12440 — CVSS 9.6 critical · EPSS 0.3% · published 2026-06-17
  • CVE-2026-14425 — CVSS 9.6 critical · EPSS 0.2% · published 2026-07-01
  • CVE-2026-14417 — CVSS 9.6 critical · EPSS 0.1% · published 2026-07-01
  • CVE-2026-16424 — CVSS 9.6 critical · EPSS 0.1% · published 2026-07-21
  • CVE-2026-102306 — CVSS 9.6 critical · published 2026-09-29
  • CVE-2026-40402 — CVSS 9.3 critical · EPSS 0.0% · published 2026-05-12
  • CVE-2026-42985 — CVSS 8.8 high · EPSS 0.9% · published 2026-06-09
  • CVE-2026-85893 — CVSS 8.8 high · EPSS 0.6% · published 2026-09-15
  • CVE-2026-10882 — CVSS 8.8 high · EPSS 0.4% · published 2026-06-04
  • CVE-2026-16806 — CVSS 8.8 high · EPSS 0.4% · published 2026-07-23
  • CVE-2026-12442 — CVSS 8.8 high · EPSS 0.3% · published 2026-06-17
  • CVE-2026-16805 — CVSS 8.8 high · EPSS 0.3% · published 2026-07-23
  • CVE-2026-12439 — CVSS 8.8 high · EPSS 0.3% · published 2026-06-17
  • CVE-2026-12441 — CVSS 8.8 high · EPSS 0.2% · published 2026-06-17

Affected vendors

Threat activity

92 tracked threats cite CWE-416; the 25 most recent are listed.

Mitigations

  • Architecture and Design / Language Selection: Choose a language that provides automatic memory management.
  • Implementation / Attack Surface Reduction: When freeing pointers, be sure to set them to NULL once they are freed. However, the utilization of multiple or complex data structures may lower the usefulness of this strategy.

Source: MITRE CWE, potential mitigations.

Detection methods (MITRE CWE)

  • Fuzzing (effectiveness: High): Fuzz testing (fuzzing) is a powerful technique for generating large numbers of diverse inputs - either randomly or algorithmically - and dynamically invoking the code with those inputs. Even with random inputs, it is often capable of generating unexpected results such as crashes, memory corruption, or resource consumption. Fuzzing effectively produces repeatable test cases that clearly indicate bugs, which helps developers to diagnose the issues.
  • Automated Static Analysis (effectiveness: High): Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)
  • Automated Dynamic Analysis (effectiveness: Moderate): Use tools that are integrated during compilation to insert runtime error-checking mechanisms related to memory safety errors, such as AddressSanitizer (ASan) for C/C++ [REF-1518].

Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.