# CWE-693: Protection Mechanism Failure

**KEV-linked**

> As of 2026-10-05, CWE-693 (Protection Mechanism Failure) underlies 18 CVEs tracked by Threadlinqs, 4 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 67 tracked threats.

**Last updated:** 2026-10-05

## What is CWE-693?

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

This weakness covers three distinct situations. A "missing" protection mechanism occurs when the application does not define any mechanism against a certain class of attack. An "insufficient" protection mechanism might provide some defenses - for example, against the most common attacks - but it does not protect against everything that is intended. Finally, an "ignored" mechanism occurs when a mechanism is available and in active use within the product, but the developer has not applied it in some code path.

CWE-693 is a pillar-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: Not Language-Specific; Technology: Not Technology-Specific; Technology: ICS/OT.

_Source: [MITRE CWE](https://cwe.mitre.org/data/definitions/693.html) (CWE-693 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data._

## Consequences

- **Access Control** — Bypass Protection Mechanism

_Source: MITRE CWE, common consequences._

## How CWE-693 is exploited in the wild

Threadlinqs maps 18 CVEs to CWE-693, published between 2025-12-26 and 2026-08-29. 4 are listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild. By CVSS v3 severity the set splits into 3 critical, 8 high, 6 medium. The highest EPSS score in the set is 70.6% (CVE-2025-40536), the modelled probability of exploitation in the next 30 days. 67 tracked threats reference CWE-693 directly or through a CVE it covers; the most recent is “Endor Labs Discloses 14 Critical/High Vulnerabilities Across Seven AI Orchestration Platforms (NocoBase, Flowise, Langflow, Dify, Activepieces, Kestra, Apache Airflow)” (2026-09-10). Affected products concentrate in Microsoft (7), Google (4), N8n (3), among 11 vendors in total.

## Vulnerabilities (CVEs)

All 18 CVEs mapped to CWE-693, CISA KEV first, then by CVSS score.

- [CVE-2026-21513](https://intel.threadlinqs.com/cve/CVE-2026-21513) — CISA KEV · CVSS 8.8 high · EPSS 27.9% · published 2026-02-10
- [CVE-2026-21510](https://intel.threadlinqs.com/cve/CVE-2026-21510) — CISA KEV · CVSS 8.8 high · EPSS 3.5% · published 2026-02-10
- [CVE-2025-40536](https://intel.threadlinqs.com/cve/CVE-2025-40536) — CISA KEV · CVSS 8.1 high · EPSS 70.6% · published 2026-01-28
- [CVE-2026-32202](https://intel.threadlinqs.com/cve/CVE-2026-32202) — CISA KEV · CVSS 4.3 medium · EPSS 7.1% · published 2026-04-14
- [CVE-2026-25115](https://intel.threadlinqs.com/cve/CVE-2026-25115) — CVSS 9.9 critical · EPSS 0.0% · published 2026-02-04
- [CVE-2025-68668](https://intel.threadlinqs.com/cve/CVE-2025-68668) — CVSS 9.9 critical · EPSS 0.0% · published 2025-12-26
- [CVE-2026-74790](https://intel.threadlinqs.com/cve/CVE-2026-74790) — CVSS 9.1 critical · published 2026-08-16
- [CVE-2026-25056](https://intel.threadlinqs.com/cve/CVE-2026-25056) — CVSS 8.8 high · EPSS 0.1% · published 2026-02-04
- [CVE-2025-69264](https://intel.threadlinqs.com/cve/CVE-2025-69264) — CVSS 8.8 high · EPSS 0.1% · published 2026-01-07
- [CVE-2026-12438](https://intel.threadlinqs.com/cve/CVE-2026-12438) — CVSS 8.3 high · EPSS 0.2% · published 2026-06-17
- [CVE-2026-22112](https://intel.threadlinqs.com/cve/CVE-2026-22112) — CVSS 7.8 high · EPSS 43.1% · published 2026-02-20
- [CVE-2026-82474](https://intel.threadlinqs.com/cve/CVE-2026-82474) — CVSS 7.8 high · EPSS 0.1% · published 2026-08-29
- [CVE-2026-34348](https://intel.threadlinqs.com/cve/CVE-2026-34348) — CVSS 6.5 medium · EPSS 0.7% · published 2026-07-14
- [CVE-2026-3965](https://intel.threadlinqs.com/cve/CVE-2026-3965) — CVSS 6.3 medium · EPSS 0.1% · published 2026-03-12
- [CVE-2026-50661](https://intel.threadlinqs.com/cve/CVE-2026-50661) — CVSS 6.1 medium · published 2026-07-14
- [CVE-2026-9116](https://intel.threadlinqs.com/cve/CVE-2026-9116) — CVSS 4.3 medium · EPSS 0.0% · published 2026-05-20
- [CVE-2026-9115](https://intel.threadlinqs.com/cve/CVE-2026-9115) — CVSS 4.3 medium · EPSS 0.0% · published 2026-05-20
- [CVE-2026-73083](https://intel.threadlinqs.com/cve/CVE-2026-73083) — EPSS 0.1% · published 2026-08-11

## Affected vendors

- [Microsoft](https://intel.threadlinqs.com/vendors/microsoft) — 7 CVEs
- [Google](https://intel.threadlinqs.com/vendors/google) — 4 CVEs
- [N8n](https://intel.threadlinqs.com/vendors/n8n) — 3 CVEs
- [Apple](https://intel.threadlinqs.com/vendors/apple) — 2 CVEs
- [Linux](https://intel.threadlinqs.com/vendors/linux) — 2 CVEs
- **Pnpm** — 1 CVE
- [Solarwinds](https://intel.threadlinqs.com/vendors/solarwinds) — 1 CVE
- **Whyour** — 1 CVE
- **activepieces** — 1 CVE
- [scriban](https://intel.threadlinqs.com/vendors/scriban) — 1 CVE
- **sudo-project** — 1 CVE

## Threat activity

67 tracked threats cite CWE-693; the 25 most recent are listed.

- [Endor Labs Discloses 14 Critical/High Vulnerabilities Across Seven AI Orchestration Platforms (NocoBase, Flowise, Langflow, Dify, Activepieces, Kestra, Apache Airflow)](https://intel.threadlinqs.com/threat/TL-2026-2438) — CRITICAL · 2026-09-10
- [ServiceNow Patches Four Critical Flaws Including Three CVSS 10.0 Unauthenticated RCE/SQLi Bugs (CVE-2026-18885, CVE-2026-18886, CVE-2026-74820, CVE-2026-6876)](https://intel.threadlinqs.com/threat/TL-2026-2195) — CRITICAL · 2026-08-28
- [Adobe and Nvidia Patch Dozens of Vulnerabilities Across Multiple Products, Including Two Critical Flaws in Nvidia's NemoClaw AI Agent Stack and a CVSS 10.0 Adobe Campaign Classic Chain](https://intel.threadlinqs.com/threat/TL-2026-2152) — CRITICAL · 2026-08-26
- [Google Chrome 151 Update Fixes 41 Security Vulnerabilities, Including 6 Critical Flaws](https://intel.threadlinqs.com/threat/TL-2026-1931) — CRITICAL · 2026-08-07
- [Pass-ta-key: Novel Attack Surface in Google Password Manager Synced Passkey Authentication](https://intel.threadlinqs.com/threat/TL-2026-1842) — CRITICAL · 2026-08-03
- [Apache Syncope Patches 12 CVEs Including Groovy Sandbox Bypass RCE and Audit Search SQLi](https://intel.threadlinqs.com/threat/TL-2026-1666) — CRITICAL · 2026-07-24
- [Exposed Server Reveals AI-Assisted WebDAV Phishing Kit Targeting Mexican Users (CVE-2025-33053)](https://intel.threadlinqs.com/threat/TL-2026-1566) — HIGH · 2026-07-20
- [HOLLOWGRAPH: Microsoft 365 Calendar-Based C2 Malware Targeting Israeli Organizations (Cavern Manticore)](https://intel.threadlinqs.com/threat/TL-2026-1567) — HIGH · 2026-07-20
- [July 2026 Patch Tuesday: Actively Exploited SharePoint RCE (CVE-2026-58644) and AD FS/SharePoint Zero-Days](https://intel.threadlinqs.com/threat/TL-2026-1437) — CRITICAL · 2026-07-17
- [Actively Exploited SonicWall SMA1000 Zero-Days (CVE-2026-15409, CVE-2026-15410) Chained for Full Appliance Takeover Alongside Microsoft July 2026 Patch Tuesday (570 CVEs, 3 Zero-Days incl. SharePoint & AD FS EoP)](https://intel.threadlinqs.com/threat/TL-2026-1451) — CRITICAL · 2026-07-17
- [Daxin Kernel Rootkit Resurfaces in Taiwan Alongside New Stupig Pre-Auth SYSTEM Backdoor](https://intel.threadlinqs.com/threat/TL-2026-1404) — CRITICAL · 2026-07-16
- [CVE-2026-50661: Windows BitLocker Security Feature Bypass 0-Day](https://intel.threadlinqs.com/threat/TL-2026-1346) — MEDIUM · 2026-07-15
- [Multiple Notepad++ Vulnerabilities Enable PowerShell Command Injection, Stack Buffer Overflow, and Zip Slip Path Traversal (CVE-2026-52886, CVE-2026-54758, CVE-2026-57233)](https://intel.threadlinqs.com/threat/TL-2026-1348) — MEDIUM · 2026-07-15
- [Microsoft July 2026 Patch Tuesday: Two Actively Exploited Zero-Days in AD FS (CVE-2026-56155) and SharePoint (CVE-2026-56164), Plus Unpatched BitLocker Bypass (CVE-2026-50661)](https://intel.threadlinqs.com/threat/TL-2026-1350) — CRITICAL · 2026-07-15
- [TuxBot v3 Evolution: LLM-Assisted IoT Botnet Framework With a Broken Multi-CVE Exploit Chain](https://intel.threadlinqs.com/threat/TL-2026-1366) — HIGH · 2026-07-15
- [July 2026 Patch Tuesday: Microsoft Fixes 622 CVEs Including Three Actively-Targeted Zero-Days (CVE-2026-56155 AD FS EoP, CVE-2026-56164 SharePoint EoP, CVE-2026-50661 BitLocker Bypass)](https://intel.threadlinqs.com/threat/TL-2026-1372) — CRITICAL · 2026-07-15
- [Microsoft July 2026 Patch Tuesday: 570 Flaws Fixed, 3 Zero-Days Including AD FS and SharePoint Privilege Escalation](https://intel.threadlinqs.com/threat/TL-2026-1324) — CRITICAL · 2026-07-14
- [Microsoft July 2026 Patch Tuesday: 570 Vulnerabilities Fixed, Including 2 Actively Exploited Zero-Days (CVE-2026-56164, CVE-2026-56155)](https://intel.threadlinqs.com/threat/TL-2026-1325) — CRITICAL · 2026-07-14
- [Windows 10 KB5099539 Extended Security Update Patches July 2026 Patch Tuesday Zero-Days — AD FS (CVE-2026-56155), SharePoint (CVE-2026-56164) Exploited; BitLocker (CVE-2026-50661) Publicly Disclosed](https://intel.threadlinqs.com/threat/TL-2026-1326) — HIGH · 2026-07-14
- [Microsoft July 2026 Patch Tuesday: 569 CVEs, Two Actively Exploited Zero-Days (CVE-2026-56155 AD FS EoP, CVE-2026-56164 SharePoint EoP)](https://intel.threadlinqs.com/threat/TL-2026-1327) — CRITICAL · 2026-07-14
- [Microsoft July 2026 Patch Tuesday: 570 Vulnerabilities Including Two Under Active Exploitation (CVE-2026-56155, CVE-2026-56164)](https://intel.threadlinqs.com/threat/TL-2026-1330) — HIGH · 2026-07-14
- [Microsoft July 2026 Patch Tuesday: Record 622 CVEs Include Two Actively Exploited Zero-Days in AD FS (CVE-2026-56155) and SharePoint Server (CVE-2026-56164)](https://intel.threadlinqs.com/threat/TL-2026-1331) — CRITICAL · 2026-07-14
- [The Gentlemen RaaS overtakes Qilin as #1 ransomware operation, wields GentleKiller EDR-killer framework (400+ processes, 8 BYOVD variants) and 90% affiliate payouts](https://intel.threadlinqs.com/threat/TL-2026-1332) — HIGH · 2026-07-14
- [Microsoft July 2026 Patch Tuesday: Record 622 Flaws Fixed, Two Zero-Days Under Active Exploitation (CVE-2026-56164, CVE-2026-56155)](https://intel.threadlinqs.com/threat/TL-2026-1334) — CRITICAL · 2026-07-14
- [Microsoft July 2026 Patch Tuesday: Two Actively Exploited Zero-Days in AD FS and SharePoint (CVE-2026-56155, CVE-2026-56164)](https://intel.threadlinqs.com/threat/TL-2026-1336) — CRITICAL · 2026-07-14

Canonical: https://intel.threadlinqs.com/cwe/CWE-693
Source definition: https://cwe.mitre.org/data/definitions/693.html
Detection rules and IOCs for threats exploiting CWE-693 via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
