# CWE-522: Insufficiently Protected Credentials

**KEV-linked**

> As of 2026-10-05, CWE-522 (Insufficiently Protected Credentials) underlies 8 CVEs tracked by Threadlinqs, 1 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 209 tracked threats.

**Last updated:** 2026-10-05

## What is CWE-522?

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

CWE-522 is a class-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: Not Language-Specific; Technology: Not Technology-Specific; Technology: Web Based; Technology: ICS/OT.

_Source: [MITRE CWE](https://cwe.mitre.org/data/definitions/522.html) (CWE-522 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data._

## Consequences

- **Access Control** — Gain Privileges or Assume Identity. An attacker could gain access to user accounts and access sensitive data used by the user accounts.

_Source: MITRE CWE, common consequences._

## How CWE-522 is exploited in the wild

Threadlinqs maps 8 CVEs to CWE-522, published between 2020-09-09 and 2026-09-25. 1 is listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild. By CVSS v3 severity the set splits into 2 critical, 2 high, 4 medium. The highest EPSS score in the set is 15.3% (CVE-2021-22681), the modelled probability of exploitation in the next 30 days. 209 tracked threats reference CWE-522 directly or through a CVE it covers; the most recent is “Kiteworks 9.5.1 Patches 126 Vulnerabilities Including Critical Account Takeover in Core and Email Protection Gateway (CVE-2026-102147, CVE-2026-102149)” (2026-10-02). Affected products concentrate in Anthropic (1), Netcore (1), PHP Group (1), among 8 vendors in total.

## Vulnerabilities (CVEs)

All 8 CVEs mapped to CWE-522, CISA KEV first, then by CVSS score.

- [CVE-2021-22681](https://intel.threadlinqs.com/cve/CVE-2021-22681) — CISA KEV · CVSS 9.8 critical · EPSS 15.3% · published 2021-03-03
- [CVE-2026-62327](https://intel.threadlinqs.com/cve/CVE-2026-62327) — CVSS 9.1 critical · EPSS 0.3% · published 2026-07-13
- [CVE-2026-21670](https://intel.threadlinqs.com/cve/CVE-2026-21670) — CVSS 7.7 high · EPSS 0.0% · published 2026-03-12
- [CVE-2026-21852](https://intel.threadlinqs.com/cve/CVE-2026-21852) — CVSS 7.5 high · EPSS 0.0% · published 2026-01-21
- [CVE-2026-92256](https://intel.threadlinqs.com/cve/CVE-2026-92256) — CVSS 6.5 medium · EPSS 0.2% · published 2026-09-15
- [CVE-2020-15791](https://intel.threadlinqs.com/cve/CVE-2020-15791) — CVSS 6.5 medium · EPSS 0.0% · published 2020-09-09
- [CVE-2026-75136](https://intel.threadlinqs.com/cve/CVE-2026-75136) — CVSS 6.1 medium · EPSS 0.1% · published 2026-09-02
- [CVE-2026-91766](https://intel.threadlinqs.com/cve/CVE-2026-91766) — CVSS 5.9 medium · published 2026-09-25

## Affected vendors

- **Anthropic** — 1 CVE
- [Netcore](https://intel.threadlinqs.com/vendors/netcore) — 1 CVE
- [PHP Group](https://intel.threadlinqs.com/vendors/php-group) — 1 CVE
- **Rockwellautomation** — 1 CVE
- **Septeo IT Solutions** — 1 CVE
- [Siemens](https://intel.threadlinqs.com/vendors/siemens) — 1 CVE
- [Veeam](https://intel.threadlinqs.com/vendors/veeam) — 1 CVE
- **decolua** — 1 CVE

## Threat activity

209 tracked threats cite CWE-522; the 25 most recent are listed.

- [Kiteworks 9.5.1 Patches 126 Vulnerabilities Including Critical Account Takeover in Core and Email Protection Gateway (CVE-2026-102147, CVE-2026-102149)](https://intel.threadlinqs.com/threat/TL-2026-2902) — CRITICAL · 2026-10-02
- [Mini Shai-Hulud: Compromised @antv npm Packages Steal Developer and CI/CD Credentials (TeamPCP)](https://intel.threadlinqs.com/threat/TL-2026-2806) — HIGH · 2026-09-30
- [Multi-Platform Data Exfiltration Across AWS and GitHub via Stolen GitHub Token and Hardcoded AWS Credentials (Wiz Blue Agent Investigation)](https://intel.threadlinqs.com/threat/TL-2026-2772) — CRITICAL · 2026-09-29
- [Infostealer-Stolen AI Service Logins Expose 80,000+ Corporate Domains (Shadow AI to LLMjacking)](https://intel.threadlinqs.com/threat/TL-2026-2757) — HIGH · 2026-09-28
- [CARBONATO Botnet Exploits Exposed Docker Daemons to Deploy AI Agent Framework, Prioritizes AI API Key Theft](https://intel.threadlinqs.com/threat/TL-2026-2689) — HIGH · 2026-09-27
- [Storm-3168 (JADEPUFFER): Agentic-Driven Destructive Cloud Attacks Against Azure via Compromised Service Principals](https://intel.threadlinqs.com/threat/TL-2026-2666) — CRITICAL · 2026-09-26
- [TokenGrabber: Python-based MaaS Infostealer Builder](https://intel.threadlinqs.com/threat/TL-2026-2643) — HIGH · 2026-09-25
- [Tax-Themed Phishing and Malware Campaign Targeting Indian Taxpayers: WhatsApp Fake ITD Notices (ITD.zip Android APK + Certum-Signed ITD_Tax_Notice.exe Loader), Cloned e-Filing Portals and Refund Scams](https://intel.threadlinqs.com/threat/TL-2026-2654) — HIGH · 2026-09-25
- [Multiple PHP Vulnerabilities Enable Denial of Service, TLS Verification Bypass, and Credential Leakage (CVE-2026-91765, CVE-2026-91768, CVE-2026-6103 and 8 Others) — GovCERT.HK A26-09-40](https://intel.threadlinqs.com/threat/TL-2026-2658) — MEDIUM · 2026-09-25
- [Google Gemini AI Model Autonomously Breached Three Real Companies During Authorized Security Evaluation](https://intel.threadlinqs.com/threat/TL-2026-2607) — MEDIUM · 2026-09-21
- [Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM APE1808 Devices (SSA-864900) — Including Actively Exploited FortiCloud SSO Bypass (CVE-2025-59718/-59719) and FortiOS Heap Overflow (CVE-2025-25249)](https://intel.threadlinqs.com/threat/TL-2026-2486) — CRITICAL · 2026-09-13
- [Adobe and Nvidia Patch Dozens of Vulnerabilities Across Multiple Products, Including Two Critical Flaws in Nvidia's NemoClaw AI Agent Stack and a CVSS 10.0 Adobe Campaign Classic Chain](https://intel.threadlinqs.com/threat/TL-2026-2152) — CRITICAL · 2026-08-26
- [CISA Red Team Fully Compromises Two Critical Infrastructure Orgs via ADCS ESC1 and AzureHound Cloud Enumeration (AA26-237A)](https://intel.threadlinqs.com/threat/TL-2026-2161) — HIGH · 2026-08-26
- [StepSecurity Dev Machine Guard adds fleet-wide developer credential inventory to close blind spot exploited by supply-chain attacks](https://intel.threadlinqs.com/threat/TL-2026-2160) — INFO · 2026-08-25
- [SDLC Supply Chain Attacks: ChainDrop npm Worm and Developer Pipeline Targeting](https://intel.threadlinqs.com/threat/TL-2026-2104) — HIGH · 2026-08-21
- [Insider Threat Landscape: Dark Web Recruitment & Access Broker Trends — July 2026](https://intel.threadlinqs.com/threat/TL-2026-2078) — MEDIUM · 2026-08-20
- [Popular Rust Packages With 244M Downloads Compromised in Supply Chain Attack](https://intel.threadlinqs.com/threat/TL-2026-2083) — CRITICAL · 2026-08-20
- [AI-Powered Attacks Targeting Siemens S7 Series PLCs in U.S. Critical Infrastructure](https://intel.threadlinqs.com/threat/TL-2026-2076) — CRITICAL · 2026-08-19
- [Operation ASTERIX: AI-Assisted Crypto Wallet Phishing/Vishing Fraud Pipeline Abuses Claude Code and Kimi](https://intel.threadlinqs.com/threat/TL-2026-2056) — HIGH · 2026-08-18
- [Azure Credential Theft Campaign Exposes Millions of Enterprise Records at McDonald's, Vodafone, TCS](https://intel.threadlinqs.com/threat/TL-2026-2028) — HIGH · 2026-08-16
- [OAuth-Token Supply-Chain Compromise Enables Attacker Access to Google Workspace: The Vercel and Composio Breaches](https://intel.threadlinqs.com/threat/TL-2026-2018) — HIGH · 2026-08-14
- [Token Jacking: Cybercriminals Steal and Resell AI API Keys/Tokens via Transfer Stations](https://intel.threadlinqs.com/threat/TL-2026-1911) — HIGH · 2026-08-06
- [GOLD ENCOUNTER / Payouts King Ransomware Campaign Targeting Business Managers: 351 Victims Across 334 Organizations](https://intel.threadlinqs.com/threat/TL-2026-1917) — HIGH · 2026-08-06
- [Pass-ta-Key Attacks Let Malware Hijack Google Password Manager Synchronized Passkeys (Chrome on Windows)](https://intel.threadlinqs.com/threat/TL-2026-1886) — HIGH · 2026-08-05
- [Shai-Hulud NPM Worm Compromises keyv, file-entry-cache, flat-cache and Hundreds of Popular npm Packages via Maintainer Account Takeover](https://intel.threadlinqs.com/threat/TL-2026-1863) — CRITICAL · 2026-08-04

## Mitigations

- **Architecture and Design**: Use an appropriate security mechanism to protect the credentials.
- **Architecture and Design**: Make appropriate use of cryptography to protect the credentials.
- **Implementation**: Use industry standards to protect the credentials (e.g. LDAP, keystore, etc.).

_Source: MITRE CWE, potential mitigations._

## Detection methods (MITRE CWE)

- **Automated Static Analysis** (effectiveness: High): Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)

_Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher._

## Related weaknesses

- [CWE-1390 Weak Authentication](https://intel.threadlinqs.com/cwe/CWE-1390)
- [CWE-287 Improper Authentication](https://intel.threadlinqs.com/cwe/CWE-287)
- [CWE-668 Exposure of Resource to Wrong Sphere](https://intel.threadlinqs.com/cwe/CWE-668)

Canonical: https://intel.threadlinqs.com/cwe/CWE-522
Source definition: https://cwe.mitre.org/data/definitions/522.html
Detection rules and IOCs for threats exploiting CWE-522 via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
