Threadlinqs IntelligenceStart free

Weakness · PillarCWE-693

CWE-693: Protection Mechanism Failure

KEV-linkedPillar

As of 2026-10-05, CWE-693 (Protection Mechanism Failure) underlies 18 CVEs tracked by Threadlinqs, 4 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 67 tracked threats.

CVEs
18Mapped to CWE-693
CISA KEV
4Exploited in the wild
Critical
3CVSS v3 critical CVEs
Threats
67Tracked campaigns citing it
Likelihood
—MITRE likelihood of exploit

Last updated:

What is CWE-693?

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

This weakness covers three distinct situations. A "missing" protection mechanism occurs when the application does not define any mechanism against a certain class of attack. An "insufficient" protection mechanism might provide some defenses - for example, against the most common attacks - but it does not protect against everything that is intended. Finally, an "ignored" mechanism occurs when a mechanism is available and in active use within the product, but the developer has not applied it in some code path.

CWE-693 is a pillar-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: Not Language-Specific; Technology: Not Technology-Specific; Technology: ICS/OT.

Source: MITRE CWE (CWE-693 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.

Consequences

  • Access Control — Bypass Protection Mechanism

Source: MITRE CWE, common consequences.

How CWE-693 is exploited in the wild

Threadlinqs maps 18 CVEs to CWE-693, published between 2025-12-26 and 2026-08-29. 4 are listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild. By CVSS v3 severity the set splits into 3 critical, 8 high, 6 medium. The highest EPSS score in the set is 70.6% (CVE-2025-40536), the modelled probability of exploitation in the next 30 days. 67 tracked threats reference CWE-693 directly or through a CVE it covers; the most recent is “Endor Labs Discloses 14 Critical/High Vulnerabilities Across Seven AI Orchestration Platforms (NocoBase, Flowise, Langflow, Dify, Activepieces, Kestra, Apache Airflow)” (2026-09-10). Affected products concentrate in Microsoft (7), Google (4), N8n (3), among 11 vendors in total.

Vulnerabilities (CVEs)

All 18 CVEs mapped to CWE-693, CISA KEV first, then by CVSS score.

  • CVE-2026-21513 — CISA KEV · CVSS 8.8 high · EPSS 27.9% · published 2026-02-10
  • CVE-2026-21510 — CISA KEV · CVSS 8.8 high · EPSS 3.5% · published 2026-02-10
  • CVE-2025-40536 — CISA KEV · CVSS 8.1 high · EPSS 70.6% · published 2026-01-28
  • CVE-2026-32202 — CISA KEV · CVSS 4.3 medium · EPSS 7.1% · published 2026-04-14
  • CVE-2026-25115 — CVSS 9.9 critical · EPSS 0.0% · published 2026-02-04
  • CVE-2025-68668 — CVSS 9.9 critical · EPSS 0.0% · published 2025-12-26
  • CVE-2026-74790 — CVSS 9.1 critical · published 2026-08-16
  • CVE-2026-25056 — CVSS 8.8 high · EPSS 0.1% · published 2026-02-04
  • CVE-2025-69264 — CVSS 8.8 high · EPSS 0.1% · published 2026-01-07
  • CVE-2026-12438 — CVSS 8.3 high · EPSS 0.2% · published 2026-06-17
  • CVE-2026-22112 — CVSS 7.8 high · EPSS 43.1% · published 2026-02-20
  • CVE-2026-82474 — CVSS 7.8 high · EPSS 0.1% · published 2026-08-29
  • CVE-2026-34348 — CVSS 6.5 medium · EPSS 0.7% · published 2026-07-14
  • CVE-2026-3965 — CVSS 6.3 medium · EPSS 0.1% · published 2026-03-12
  • CVE-2026-50661 — CVSS 6.1 medium · published 2026-07-14
  • CVE-2026-9116 — CVSS 4.3 medium · EPSS 0.0% · published 2026-05-20
  • CVE-2026-9115 — CVSS 4.3 medium · EPSS 0.0% · published 2026-05-20
  • CVE-2026-73083 — EPSS 0.1% · published 2026-08-11

Affected vendors

Threat activity

67 tracked threats cite CWE-693; the 25 most recent are listed.