Threadlinqs IntelligenceStart free

Weakness · ClassCWE-77

CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')

Likelihood of exploit: HighKEV-linkedClass

As of 2026-10-05, CWE-77 (Command Injection) underlies 39 CVEs tracked by Threadlinqs, 8 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 65 tracked threats. MITRE rates its likelihood of exploit as High.

CVEs
39Mapped to CWE-77
CISA KEV
8Exploited in the wild
Critical
17CVSS v3 critical CVEs
Threats
65Tracked campaigns citing it
Likelihood
HighMITRE likelihood of exploit

Last updated:

What is CWE-77?

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Many protocols and products have their own custom command language. While OS or shell command strings are frequently discovered and targeted, developers may not realize that these other command languages might also be vulnerable to attacks.

CWE-77 is a class-level weakness in MITRE’s Common Weakness Enumeration, with a MITRE likelihood of exploit of High. Applicable platforms: Language: Not Language-Specific; Technology: AI/ML.

Source: MITRE CWE (CWE-77 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.

Consequences

  • Integrity, Confidentiality, Availability — Execute Unauthorized Code or Commands. If a malicious user injects a character (such as a semi-colon) that delimits the end of one command and the beginning of another, it may be possible to then insert an entirely new and unrelated command that was not intended to be executed. This gives an attacker a privilege or capability that they would not otherwise have.

Source: MITRE CWE, common consequences.

How CWE-77 is exploited in the wild

Threadlinqs maps 39 CVEs to CWE-77, published between 2012-05-11 and 2026-09-29. 8 are listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild, and 3 are tied to ransomware campaigns. By CVSS v3 severity the set splits into 17 critical, 14 high, 7 medium. The highest EPSS score in the set is 99.9% (CVE-2024-3400), the modelled probability of exploitation in the next 30 days. 65 tracked threats reference CWE-77 directly or through a CVE it covers; the most recent is “GTIG: AI-Era Vulnerability Discovery and Exploitation Surge — In-the-Wild Exploitation of BeyondTrust CVE-2026-1731, LiteLLM CVE-2026-42271 and Langflow CVE-2026-5027” (2026-09-30). Affected products concentrate in Microsoft (6), Dlink (4), Ziroom (4), among 24 vendors in total.

Vulnerabilities (CVEs)

All 39 CVEs mapped to CWE-77, CISA KEV first, then by CVSS score.

  • CVE-2024-3400 — CISA KEV · CVSS 10 critical · EPSS 99.9% · published 2024-04-12
  • CVE-2025-10035 — CISA KEV · CVSS 10 critical · EPSS 55.7% · published 2025-09-18
  • CVE-2012-1823 — CISA KEV · CVSS 9.8 critical · EPSS 94.3% · published 2012-05-11
  • CVE-2024-12356 — CISA KEV · CVSS 9.8 critical · EPSS 93.7% · published 2024-12-17
  • CVE-2024-21887 — CISA KEV · CVSS 9.1 critical · EPSS 94.4% · published 2024-01-12
  • CVE-2026-42271 — CISA KEV · CVSS 8.8 high · EPSS 92.5% · published 2026-05-08
  • CVE-2026-22719 — CISA KEV · CVSS 8.1 high · EPSS 2.3% · published 2026-02-25
  • CVE-2025-29635 — CISA KEV · CVSS 7.2 high · EPSS 1.2% · published 2025-03-25
  • CVE-2026-82971 — CVSS 10 critical · EPSS 1.8% · published 2026-08-31
  • CVE-2026-83524 — CVSS 9.9 critical · EPSS 1.6% · published 2026-08-31
  • CVE-2026-85885 — CVSS 9.9 critical · EPSS 0.5% · published 2026-09-17
  • CVE-2026-15511 — CVSS 9.8 critical · EPSS 2.6% · published 2026-07-12
  • CVE-2026-18684 — CVSS 9.8 critical · EPSS 2.0% · published 2026-08-03
  • CVE-2026-32194 — CVSS 9.8 critical · EPSS 0.7% · published 2026-03-19
  • CVE-2026-86148 — CVSS 9.1 critical · EPSS 2.4% · published 2026-09-05
  • CVE-2026-101261 — CVSS 9.1 critical · EPSS 2.3% · published 2026-09-28
  • CVE-2026-101262 — CVSS 9.1 critical · EPSS 2.3% · published 2026-09-28
  • CVE-2026-101260 — CVSS 9.1 critical · EPSS 2.3% · published 2026-09-28
  • CVE-2026-86149 — CVSS 9.1 critical · EPSS 2.0% · published 2026-09-05
  • CVE-2026-102792 — CVSS 9.1 critical · published 2026-09-29
  • CVE-2026-30898 — CVSS 8.8 high · EPSS 0.7% · published 2026-04-18
  • CVE-2026-3854 — CVSS 8.8 high · EPSS 0.3% · published 2026-03-10
  • CVE-2026-23814 — CVSS 8.8 high · EPSS 0.1% · published 2026-03-11
  • CVE-2026-24301 — CVSS 8.8 high · published 2026-08-18
  • CVE-2026-79912 — CVSS 8.3 high · EPSS 1.4% · published 2026-08-25
  • CVE-2026-19960 — CVSS 7.4 high · EPSS 1.1% · published 2026-08-16
  • CVE-2026-78141 — CVSS 7.4 high · EPSS 1.0% · published 2026-08-23
  • CVE-2026-78501 — CVSS 7.4 high · EPSS 0.4% · published 2026-09-17
  • CVE-2026-2129 — CVSS 7.2 high · EPSS 0.1% · published 2026-02-08
  • CVE-2026-2142 — CVSS 7.2 high · EPSS 0.1% · published 2026-02-08
  • CVE-2026-2143 — CVSS 7.2 high · EPSS 0.1% · published 2026-02-08
  • CVE-2026-21522 — CVSS 6.7 medium · EPSS 0.0% · published 2026-02-10
  • CVE-2026-42824 — CVSS 6.5 medium · EPSS 0.5% · published 2026-06-04
  • CVE-2024-1781 — CVSS 6.3 medium · EPSS 14.6% · published 2024-02-23
  • CVE-2026-97366 — CVSS 6.3 medium · EPSS 1.1% · published 2026-09-24
  • CVE-2026-3102 — CVSS 6.3 medium · EPSS 0.0% · published 2026-02-24
  • CVE-2026-16630 — CVSS 5.3 medium · EPSS 1.0% · published 2026-07-22
  • CVE-2026-13501 — CVSS 5.3 medium · EPSS 0.6% · published 2026-06-28
  • CVE-2026-73250 — EPSS 0.1% · published 2026-08-11

Affected vendors

  • Microsoft — 6 CVEs
  • Dlink — 4 CVEs
  • Ziroom — 4 CVEs
  • Tenda — 3 CVEs
  • Apache Software Foundation — 1 CVE
  • BerriAI — 1 CVE
  • Beyondtrust — 1 CVE
  • Comfast — 1 CVE
  • Edimax — 1 CVE
  • Fortra — 1 CVE
  • GL.iNet — 1 CVE
  • Github — 1 CVE

Threat activity

65 tracked threats cite CWE-77; the 25 most recent are listed.

Mitigations

  • Architecture and Design: If at all possible, use library calls rather than external processes to recreate the desired functionality.
  • Implementation: If possible, ensure that all external commands called from the program are statically created.
  • Implementation / Input Validation: Assume all input is malicious. Use an "accept known good" input validation strategy, i.e., use a list of acceptable inputs that strictly conform to specifications. Reject any input that does not strictly conform to specifications, or transform it into something that does. When performing input validation, consider all potentially relevant properties, including length, type of input, the full range of acceptable values, missing or extra inputs, syntax, consistency across related fields, and conformance to business rules. As an example of business rule logic, "boat" may be syntactically valid because it only contains alphanumeric characters, but it is not valid if the input is only expected…
  • Operation: Run time: Run time policy enforcement may be used in an allowlist fashion to prevent use of any non-sanctioned commands.
  • System Configuration: Assign permissions that prevent the user from accessing/opening privileged files.

Source: MITRE CWE, potential mitigations.

Detection methods (MITRE CWE)

  • Automated Static Analysis (effectiveness: High): Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)

Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.