What is CWE-59?
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
CWE-59 is a base-level weakness in MITRE’s Common Weakness Enumeration, with a MITRE likelihood of exploit of Medium. Applicable platforms: Language: Not Language-Specific; Operating_System: Windows; Operating_System: Unix; Technology: Not Technology-Specific.
Source: MITRE CWE (CWE-59 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.
Consequences
- Confidentiality, Integrity, Access Control — Read Files or Directories, Modify Files or Directories, Bypass Protection Mechanism. An attacker may be able to traverse the file system to unintended locations and read or overwrite the contents of unexpected files. If the files are used for a security mechanism then an attacker may be able to bypass the mechanism.
- Other — Execute Unauthorized Code or Commands. Windows simple shortcuts, sometimes referred to as soft links, can be exploited remotely since a ".LNK" file can be uploaded like a normal file. This can enable remote execution.
Source: MITRE CWE, common consequences.
How CWE-59 is exploited in the wild
Threadlinqs maps 21 CVEs to CWE-59, published between 2025-01-15 and 2026-09-27. 4 are listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild, and 1 is tied to ransomware campaigns. By CVSS v3 severity the set splits into 10 high, 5 medium, 3 low. The highest EPSS score in the set is 20.8% (CVE-2025-60710), the modelled probability of exploitation in the next 30 days. 38 tracked threats reference CWE-59 directly or through a CVE it covers; the most recent is “Multiple High-Severity Vulnerabilities in TeamViewer Client (CVE-2026-92370, CVE-2026-92368, CVE-2026-92369, CVE-2026-92371, CVE-2026-19743)” (2026-10-02). Affected products concentrate in Microsoft (7), AnyDesk (2), Red Hat (2), among 14 vendors in total.
Vulnerabilities (CVEs)
All 21 CVEs mapped to CWE-59, CISA KEV first, then by CVSS score.
- CVE-2026-33825 — CISA KEV · CVSS 7.8 high · EPSS 7.0% · published 2026-04-14
- CVE-2026-41091 — CISA KEV · CVSS 7.8 high · EPSS 6.9% · published 2026-05-20
- CVE-2026-81963 — CISA KEV · CVSS 7.8 high · published 2026-09-08
- CVE-2025-60710 — CISA KEV · CVSS 7.5 high · EPSS 20.8% · published 2025-11-11
- CVE-2026-50656 — CVSS 7.8 high · EPSS 3.3% · published 2026-06-16
- CVE-2026-45586 — CVSS 7.8 high · EPSS 3.0% · published 2026-06-09
- CVE-2026-25187 — CVSS 7.8 high · EPSS 0.1% · published 2026-03-10
- CVE-2026-54572 — CVSS 7.5 high · EPSS 0.3% · published 2026-07-14
- CVE-2026-31979 — CVSS 7.5 high · EPSS 0.0% · published 2026-03-11
- CVE-2024-57728 — CVSS 7.2 high · EPSS 1.0% · published 2025-01-15
- CVE-2026-74796 — CVSS 6.1 medium · EPSS 0.2% · published 2026-08-16
- CVE-2026-93353 — CVSS 5.3 medium · EPSS 0.3% · published 2026-09-24
- CVE-2026-15681 — CVSS 4.7 medium · EPSS 0.1% · published 2026-07-13
- CVE-2026-15682 — CVSS 4.7 medium · EPSS 0.1% · published 2026-07-13
- CVE-2026-17459 — CVSS 4.3 medium · EPSS 0.3% · published 2026-07-26
- CVE-2026-61858 — CVSS 3.3 low · EPSS 0.1% · published 2026-07-11
- CVE-2026-96282 — CVSS 3.1 low · published 2026-09-27
- CVE-2026-96284 — CVSS 2.5 low · published 2026-09-27
- CVE-2026-71476 — EPSS 0.5% · published 2026-08-06
- CVE-2026-17106 — EPSS 0.4% · published 2026-08-18
- CVE-2025-30240 — EPSS 0.1% · published 2026-08-10
Affected vendors
- Microsoft — 7 CVEs
- AnyDesk — 2 CVEs
- Red Hat — 2 CVEs
- 9001 — 1 CVE
- Docker — 1 CVE
- Himmelblau-Idm — 1 CVE
- ImageMagick — 1 CVE
- Simple-help — 1 CVE
- TP-Link Systems Inc. — 1 CVE
- moby — 1 CVE
- nrwl — 1 CVE
- opentofu — 1 CVE
Threat activity
38 tracked threats cite CWE-59; the 25 most recent are listed.
- Multiple High-Severity Vulnerabilities in TeamViewer Client (CVE-2026-92370, CVE-2026-92368, CVE-2026-92369, CVE-2026-92371, CVE-2026-19743)HIGH
- Docker CopyEscape (CVE-2026-17106): docker cp / sbx cp flaw lets malicious containers overwrite host filesHIGH
- September 2026 Microsoft Patch Tuesday — Record 966+ Vulnerabilities with Two Actively Exploited Zero-Days (CVE-2026-81963, CVE-2026-85880) and Multiple Critical Wormable RCEsCRITICAL
- Microsoft September 2026 Patch Tuesday — 999 CVEs, 3 actively exploited zero-days (CVE-2026-85880, CVE-2026-81963, CVE-2026-85046)CRITICAL
- FalconFlank — CrowdStrike Falcon Sensor Local Privilege Escalation Zero-Day with Public PoCHIGH
- ShieldBreak: Windows Defender Cloud-Hydration Zero-Day Bypasses RoguePlanet Patch (CVE-2026-50656) for SYSTEM-Level Privilege EscalationCRITICAL
- Microsoft August 2026 Patch Tuesday: 400 Flaws Fixed, Including Lazarus-Exploited Zero-Day CVE-2026-68820 (AFD.sys) and Two Publicly Disclosed Zero-Days (CVE-2026-62832 "LegacyHive", CVE-2026-72971)CRITICAL
- Multiple Critical Vulnerabilities in Cisco Catalyst SD-WAN Software (CVE-2026-20303, CVE-2026-20304, CVE-2026-20310, CVE-2026-20312, CVE-2026-20313)CRITICAL
- NightmareEclipse Coordinated Disclosure Breach Campaign: 9+ Windows Zero-Days (CVE-2026-33825, CVE-2026-41091, CVE-2026-45498, CVE-2026-45585, CVE-2026-45586) Dumped Outside Responsible Disclosure and Weaponized in Real-World IntrusionsCRITICAL
- LegacyHive Exploitation Chain Bypasses Windows Security Even With July 2026 Patches InstalledHIGH
- Claude Code Symlink Flaw in Startup Memory Loader Enables Silent File Exfiltration via CLAUDE.md ImportsMEDIUM
- CVE-2026-8933: Race Condition in Ubuntu snap-confine Enables Local Privilege Escalation to RootHIGH
- "LegacyHive" Windows User Profile Service Zero-Day Allows Non-Admin Registry Hive HijackingHIGH
- Critical Ubuntu Pro Client Vulnerability Enables Root Code Execution via Contract Server Spoofing (CVE-2026-11386)CRITICAL
- LegacyHive: Local Privilege Escalation PoC via Windows User Profile Service (ProfSvc) Registry Hive MountingMEDIUM
- AnyDesk "Send Support Information" Link-Following Denial-of-Service (CVE-2026-15682)MEDIUM
- LegacyHive: Windows 0-Day Allows Standard Users to Load Another User's Registry Hive via User Profile ServiceHIGH
- LegacyHive: Unpatched Windows User Profile Service (profsvc) Registry Hive Hijack Privilege Escalation 0-Day PoC Released by Nightmare-EclipseHIGH
- RoguePlanet: Microsoft Defender Elevation of Privilege Vulnerability (CVE-2026-50656) PatchedHIGH
- Cursor IDE "DuneSlide" Sandbox Escape RCE via Zero-Click Prompt Injection (CVE-2026-50548, CVE-2026-50549)CRITICAL
- Critical Cursor AI Code Editor Flaws (CVE-2026-50548, CVE-2026-50549) — "DuneSlide" Zero-Click Prompt Injection to Sandbox Escape and RCECRITICAL
- Amazon Q Developer Extension Trust-Boundary & Symlink Flaws (CVE-2026-12957, CVE-2026-12958) Auto-Execute Malicious MCP ConfigsHIGH
- CVE-2026-50656: RoguePlanet Microsoft Defender Zero-Day Local Privilege Escalation (Malware Protection Engine TOCTOU)HIGH
- GhostTree / GhostBranch: Recursive NTFS Directory Junctions Abused to Evade Recursive File Scanners and Hide MalwareMEDIUM
- Windows Defender 0-Day Local Privilege Escalation "RoguePlanet" (Nightmare Eclipse Defender Exploit Series)HIGH
Mitigations
- Architecture and Design / Separation of Privilege: Follow the principle of least privilege when assigning access rights to entities in a software system. Denying access to a file can prevent an attacker from replacing that file with a link to a sensitive file. Ensure good compartmentalization in the system to provide protected areas that can be trusted.
Source: MITRE CWE, potential mitigations.
Detection methods (MITRE CWE)
- Automated Static Analysis - Binary or Bytecode (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Bytecode Weakness Analysis - including disassembler + source code weakness analysis
- Manual Static Analysis - Binary or Bytecode (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Binary / Bytecode disassembler - then use manual analysis for vulnerabilities & anomalies
- Dynamic Analysis with Automated Results Interpretation (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Web Application Scanner Web Services Scanner Database Scanners
- Dynamic Analysis with Manual Results Interpretation (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Fuzz Tester Framework-based Fuzzer
- Manual Static Analysis - Source Code (effectiveness: High): According to SOAR [REF-1479], the following detection techniques may be useful: Highly cost effective: Focused Manual Spotcheck - Focused manual analysis of source Manual Source Code Review (not inspections)
- Automated Static Analysis - Source Code (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Source code Weakness Analyzer Context-configured Source Code Weakness Analyzer
- Architecture or Design Review (effectiveness: High): According to SOAR [REF-1479], the following detection techniques may be useful: Highly cost effective: Formal Methods / Correct-By-Construction Cost effective for partial coverage: Inspection (IEEE 1028 standard) (can apply to requirements, design, source code, etc.)
Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.