What is CWE-434?
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
CWE-434 is a base-level weakness in MITRE’s Common Weakness Enumeration, with a MITRE likelihood of exploit of Medium. Applicable platforms: Language: ASP.NET; Language: PHP; Language: Not Language-Specific; Technology: Web Server.
Source: MITRE CWE (CWE-434 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.
Consequences
- Integrity, Confidentiality, Availability — Execute Unauthorized Code or Commands. Arbitrary code execution is possible if an uploaded file is interpreted and executed as code by the recipient. This is especially true for web-server extensions such as .asp and .php because these file types are often treated as automatically executable, even when file system permissions do not specify execution. For example, in Unix environments, programs typically cannot run unless the execute bit is set, but PHP programs may be executed by the web server without directly invoking them on the…
Source: MITRE CWE, common consequences.
How CWE-434 is exploited in the wild
Threadlinqs maps 31 CVEs to CWE-434, published between 2020-09-09 and 2026-09-26. 5 are listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild, and 1 is tied to ransomware campaigns. By CVSS v3 severity the set splits into 17 critical, 5 high, 5 medium. The highest EPSS score in the set is 97.3% (CVE-2020-25213), the modelled probability of exploitation in the next 30 days. 71 tracked threats reference CWE-434 directly or through a CVE it covers; the most recent is “Kiteworks 9.5.1 Patches 126 Vulnerabilities Including Critical Account Takeover in Core and Email Protection Gateway (CVE-2026-102147, CVE-2026-102149)” (2026-10-02). Affected products concentrate in Microsoft (2), N8n (2), SourceCodester (2), among 27 vendors in total.
Vulnerabilities (CVEs)
All 31 CVEs mapped to CWE-434, CISA KEV first, then by CVSS score.
- CVE-2020-25213 — CISA KEV · CVSS 10 critical · EPSS 97.3% · published 2020-09-09
- CVE-2025-52691 — CISA KEV · CVSS 10 critical · EPSS 87.2% · published 2025-12-29
- CVE-2026-48939 — CISA KEV · CVSS 9.8 critical · EPSS 1.5% · published 2026-06-20
- CVE-2026-56291 — CISA KEV · CVSS 9.8 critical · EPSS 0.8% · published 2026-07-09
- CVE-2021-31207 — CISA KEV · CVSS 6.6 medium · EPSS 93.8% · published 2021-05-11
- CVE-2026-48276 — CVSS 10 critical · EPSS 0.9% · published 2026-06-30
- CVE-2026-21877 — CVSS 9.9 critical · EPSS 14.1% · published 2026-01-08
- CVE-2026-3844 — CVSS 9.8 critical · EPSS 36.5% · published 2026-04-23
- CVE-2026-1357 — CVSS 9.8 critical · EPSS 15.8% · published 2026-02-11
- CVE-2020-36847 — CVSS 9.8 critical · EPSS 12.6% · published 2025-07-12
- CVE-2024-4345 — CVSS 9.8 critical · EPSS 1.4% · published 2024-05-07
- CVE-2026-82901 — CVSS 9.8 critical · EPSS 1.1% · published 2026-09-26
- CVE-2026-93352 — CVSS 9.8 critical · EPSS 0.6% · published 2026-09-23
- CVE-2026-21536 — CVSS 9.8 critical · EPSS 0.4% · published 2026-03-05
- CVE-2026-84637 — CVSS 9.8 critical · EPSS 0.1% · published 2026-09-01
- CVE-2026-15748 — CVSS 9.8 critical · published 2026-08-18
- CVE-2026-2701 — CVSS 9.1 critical · EPSS 0.2% · published 2026-04-02
- CVE-2026-27540 — CVSS 9 critical · EPSS 2.3% · published 2026-03-19
- CVE-2026-25056 — CVSS 8.8 high · EPSS 0.1% · published 2026-02-04
- CVE-2025-7443 — CVSS 8.1 high · EPSS 0.6% · published 2025-08-01
- CVE-2026-90603 — CVSS 7.3 high · EPSS 0.4% · published 2026-09-13
- CVE-2026-82921 — CVSS 7.3 high · EPSS 0.2% · published 2026-08-31
- CVE-2026-82524 — CVSS 7.2 high · EPSS 0.3% · published 2026-09-02
- CVE-2026-95820 — CVSS 6.3 medium · EPSS 0.3% · published 2026-09-22
- CVE-2026-14775 — CVSS 6.3 medium · EPSS 0.2% · published 2026-07-05
- CVE-2026-14776 — CVSS 6.3 medium · EPSS 0.2% · published 2026-07-05
- CVE-2026-1969 — CVSS 5.3 medium · EPSS 0.1% · published 2026-03-23
- CVE-2026-57311 — EPSS 0.3% · published 2026-07-20
- CVE-2026-81931 — EPSS 0.2% · published 2026-08-27
- CVE-2026-74767 — EPSS 0.2% · published 2026-08-15
- CVE-2026-61448 — EPSS 0.2% · published 2026-07-11
Affected vendors
- Microsoft — 2 CVEs
- N8n — 2 CVEs
- SourceCodester — 2 CVEs
- Adobe — 1 CVE
- Anil-matcha — 1 CVE
- Filemanagerpro — 1 CVE
- JCD — 1 CVE
- Mozilla — 1 CVE
- Progress — 1 CVE
- Roskus — 1 CVE
- Rymera Web Co Pty Ltd. — 1 CVE
- ShopEx — 1 CVE
Threat activity
71 tracked threats cite CWE-434; the 25 most recent are listed.
- Kiteworks 9.5.1 Patches 126 Vulnerabilities Including Critical Account Takeover in Core and Email Protection Gateway (CVE-2026-102147, CVE-2026-102149)CRITICAL
- Check Point Patches Actively Exploited Zero-Day Path Traversal in Management Server (CVE-2026-93616)CRITICAL
- ShinyHunters Hacks Clop Ransomware Gang's Tor Leak Site via Grav CMS File Upload Flaw, Threatens 72-Hour ExtortionMEDIUM
- CVE-2026-27540: Unauthenticated Arbitrary File Upload in WooCommerce Wholesale Lead Capture Plugin Actively ExploitedCRITICAL
- Recorded Future H1 2026 Report: Actively Exploited CVEs Up 34%, Ransomware Adopts BYOVD and Post-Quantum CryptoHIGH
- FamousSparrow APT Targets Azerbaijani Oil & Gas Sector via ProxyShell/ProxyNotShell Exchange ExploitationCRITICAL
- Critical Elementor Pro unauthenticated file upload vulnerability leads to RCE on WordPress sites (CVE-2026-32475)CRITICAL
- AI-Powered Attacks Targeting Siemens S7 Series PLCs in U.S. Critical InfrastructureCRITICAL
- StopAndProtect: Compromised WordPress Sites Used as Malware Distribution Infrastructure for Ransomware, Stealer, and Worm PayloadsHIGH
- CVE-2026-15748: Forminator WordPress Plugin Arbitrary File Upload Enables Unauthenticated RCECRITICAL
- China-Linked Actor Uses Autonomous AI Agent Frameworks (Hermes, OpenClaw) to Breach Taiwan Government and Critical InfrastructureCRITICAL
- WordPress Core XSS2Shell Vulnerability Chains Pre-Auth XSS to RCE (CVE-2026-64638)HIGH
- Cyble H1 2026 Threat Actor Landscape: 261 Tracked Groups, Five Most Active Actors ProfiledHIGH
- UT Dallas Study: Multi-Patch CVE Fixes Leave Open Source Exposed to N-Day Exploitation WindowsMEDIUM
- BlackCat/ALPHV Ransomware Abuses Azure Storage Account Keys via Sphynx Encryptor to Mass-Encrypt Cloud StorageHIGH
- Command Injection Vulnerabilities in Bing Images Processing Pipeline (CVE-2026-32194, CVE-2026-32191, CVE-2026-21536) — RCE as NT AUTHORITY\SYSTEMCRITICAL
- Kaseya VSA Supply-Chain Ransomware Incident — REvil/Sodinokibi Exploits CVE-2021-30116/30117/30118/30119/30120/30121 to Compromise 60 MSPs and 1,500+ Downstream OrganizationsCRITICAL
- Dolphin X Stealer — MaaS Credential/Crypto Infostealer with AI-Driven Victim Profiler (thedolphinx[.]top)HIGH
- SolarWinds Serv-U 2026.3 Patches 16 Vulnerabilities (CVE-2026-28302 to CVE-2026-28321) Including Root RCE, IDOR-Chained Privilege Escalation, and Broken Access ControlCRITICAL
- Oracle Hospitality Simphony Vulnerabilities: NTLM Hash Disclosure, Arbitrary File Write, and Kiosk Authentication Bypass (CVE-2026-60167, CVE-2026-60168, CVE-2026-60169, CVE-2026-60170)CRITICAL
- CVE-2026-57309: Unauthenticated Blind SQL Injection in Windu CMS 4.1 (with CVE-2026-57310 Weak Password Hashing and CVE-2026-57311 Unrestricted File Upload)HIGH
- HelloNet Campaign Abuses ViPNet Update Mechanism to Deploy HelloInjector/HelloProxy/HelloBackdoor Toolset Against Russian Government AgenciesHIGH
- wp2shell RCE Chain in WordPress Core (CVE-2026-60137, CVE-2026-63030) — Emergency Patch ReleasedCRITICAL
- Spirals Ransomware Targets South Asian IT Services Firm via IIS Web Shell, Chisel Tunneling, and Sub-24-Hour EncryptionHIGH
- wp2shell: WordPress Core REST API Batch-Route Confusion Chained with author__not_in SQL Injection (CVE-2026-63030 / CVE-2026-60137) Yields Unauthenticated Pre-Auth RCECRITICAL
Mitigations
- Architecture and Design: Generate a new, unique filename for an uploaded file instead of using the user-supplied filename, so that no external input is used at all.[REF-422] [REF-423]
- Architecture and Design / Enforcement by Conversion: When the set of acceptable objects, such as filenames or URLs, is limited or known, create a mapping from a set of fixed input values (such as numeric IDs) to the actual filenames or URLs, and reject all other inputs.
- Architecture and Design: Consider storing the uploaded files outside of the web document root entirely. Then, use other mechanisms to deliver the files dynamically. [REF-423]
- Implementation / Input Validation: Assume all input is malicious. Use an "accept known good" input validation strategy, i.e., use a list of acceptable inputs that strictly conform to specifications. Reject any input that does not strictly conform to specifications, or transform it into something that does. When performing input validation, consider all potentially relevant properties, including length, type of input, the full range of acceptable values, missing or extra inputs, syntax, consistency across related fields, and conformance to business rules. As an example of business rule logic, "boat" may be syntactically valid because it only contains alphanumeric characters, but it is not valid if the input is only expected…
- Architecture and Design: Define a very limited set of allowable extensions and only generate filenames that end in these extensions. Consider the possibility of XSS (CWE-79) before allowing .html or .htm file types.
- Implementation / Input Validation: Ensure that only one extension is used in the filename. Some web servers, including some versions of Apache, may process files based on inner extensions so that "filename.php.gif" is fed to the PHP interpreter.[REF-422] [REF-423]
- Implementation: When running on a web server that supports case-insensitive filenames, perform case-insensitive evaluations of the extensions that are provided.
- Architecture and Design: For any security checks that are performed on the client side, ensure that these checks are duplicated on the server side, in order to avoid CWE-602. Attackers can bypass the client-side checks by modifying values after the checks have been performed, or by changing the client to remove the client-side checks entirely. Then, these modified values would be submitted to the server.
- Implementation: Do not rely exclusively on sanity checks of file contents to ensure that the file is of the expected type and size. It may be possible for an attacker to hide code in some file segments that will still be executed by the server. For example, GIF images may contain a free-form comments field.
- Implementation: Do not rely exclusively on the MIME content type or filename attribute when determining how to render a file. Validating the MIME content type and ensuring that it matches the extension is only a partial solution.
Source: MITRE CWE, potential mitigations.
Detection methods (MITRE CWE)
- Dynamic Analysis with Automated Results Interpretation (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Web Application Scanner Web Services Scanner Database Scanners
- Dynamic Analysis with Manual Results Interpretation (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Fuzz Tester Framework-based Fuzzer
- Manual Static Analysis - Source Code (effectiveness: High): According to SOAR [REF-1479], the following detection techniques may be useful: Highly cost effective: Focused Manual Spotcheck - Focused manual analysis of source Manual Source Code Review (not inspections)
- Automated Static Analysis - Source Code (effectiveness: High): According to SOAR [REF-1479], the following detection techniques may be useful: Highly cost effective: Source code Weakness Analyzer Context-configured Source Code Weakness Analyzer
- Architecture or Design Review (effectiveness: High): According to SOAR [REF-1479], the following detection techniques may be useful: Highly cost effective: Formal Methods / Correct-By-Construction Cost effective for partial coverage: Inspection (IEEE 1028 standard) (can apply to requirements, design, source code, etc.)
Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.