Threadlinqs IntelligenceStart free

Weakness · ClassCWE-522

CWE-522: Insufficiently Protected Credentials

KEV-linkedClass

As of 2026-10-05, CWE-522 (Insufficiently Protected Credentials) underlies 8 CVEs tracked by Threadlinqs, 1 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 209 tracked threats.

CVEs
8Mapped to CWE-522
CISA KEV
1Exploited in the wild
Critical
2CVSS v3 critical CVEs
Threats
209Tracked campaigns citing it
Likelihood
—MITRE likelihood of exploit

Last updated:

What is CWE-522?

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

CWE-522 is a class-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: Not Language-Specific; Technology: Not Technology-Specific; Technology: Web Based; Technology: ICS/OT.

Source: MITRE CWE (CWE-522 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.

Consequences

  • Access Control — Gain Privileges or Assume Identity. An attacker could gain access to user accounts and access sensitive data used by the user accounts.

Source: MITRE CWE, common consequences.

How CWE-522 is exploited in the wild

Threadlinqs maps 8 CVEs to CWE-522, published between 2020-09-09 and 2026-09-25. 1 is listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild. By CVSS v3 severity the set splits into 2 critical, 2 high, 4 medium. The highest EPSS score in the set is 15.3% (CVE-2021-22681), the modelled probability of exploitation in the next 30 days. 209 tracked threats reference CWE-522 directly or through a CVE it covers; the most recent is “Kiteworks 9.5.1 Patches 126 Vulnerabilities Including Critical Account Takeover in Core and Email Protection Gateway (CVE-2026-102147, CVE-2026-102149)” (2026-10-02). Affected products concentrate in Anthropic (1), Netcore (1), PHP Group (1), among 8 vendors in total.

Vulnerabilities (CVEs)

All 8 CVEs mapped to CWE-522, CISA KEV first, then by CVSS score.

  • CVE-2021-22681 — CISA KEV · CVSS 9.8 critical · EPSS 15.3% · published 2021-03-03
  • CVE-2026-62327 — CVSS 9.1 critical · EPSS 0.3% · published 2026-07-13
  • CVE-2026-21670 — CVSS 7.7 high · EPSS 0.0% · published 2026-03-12
  • CVE-2026-21852 — CVSS 7.5 high · EPSS 0.0% · published 2026-01-21
  • CVE-2026-92256 — CVSS 6.5 medium · EPSS 0.2% · published 2026-09-15
  • CVE-2020-15791 — CVSS 6.5 medium · EPSS 0.0% · published 2020-09-09
  • CVE-2026-75136 — CVSS 6.1 medium · EPSS 0.1% · published 2026-09-02
  • CVE-2026-91766 — CVSS 5.9 medium · published 2026-09-25

Affected vendors

  • Anthropic — 1 CVE
  • Netcore — 1 CVE
  • PHP Group — 1 CVE
  • Rockwellautomation — 1 CVE
  • Septeo IT Solutions — 1 CVE
  • Siemens — 1 CVE
  • Veeam — 1 CVE
  • decolua — 1 CVE

Threat activity

209 tracked threats cite CWE-522; the 25 most recent are listed.

Mitigations

  • Architecture and Design: Use an appropriate security mechanism to protect the credentials.
  • Architecture and Design: Make appropriate use of cryptography to protect the credentials.
  • Implementation: Use industry standards to protect the credentials (e.g. LDAP, keystore, etc.).

Source: MITRE CWE, potential mitigations.

Detection methods (MITRE CWE)

  • Automated Static Analysis (effectiveness: High): Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)

Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.