What is CWE-908?
The product uses or accesses a resource that has not been initialized.
When a resource has not been properly initialized, the product may behave unexpectedly. This may lead to a crash or invalid memory access, but the consequences vary depending on the type of resource and how it is used within the product.
CWE-908 is a base-level weakness in MITRE’s Common Weakness Enumeration, with a MITRE likelihood of exploit of Medium. Applicable platforms: Not Language-Specific.
Source: MITRE CWE (CWE-908 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.
Consequences
- Confidentiality — Read Memory, Read Application Data. When reusing a resource such as memory or a program variable, the original contents of that resource may not be cleared before it is sent to an untrusted party.
- Availability — DoS: Crash, Exit, or Restart. The uninitialized resource may contain values that cause program flow to change in ways that the programmer did not intend.
Source: MITRE CWE, common consequences.
How CWE-908 is exploited in the wild
Threadlinqs maps 14 CVEs to CWE-908, published between 2024-11-19 and 2026-09-29. 3 are listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild, and 1 is tied to ransomware campaigns. By CVSS v3 severity the set splits into 4 high, 9 medium, 1 low. The highest EPSS score in the set is 62.2% (CVE-2025-5777), the modelled probability of exploitation in the next 30 days. 19 tracked threats reference CWE-908 directly or through a CVE it covers; the most recent is “Google Chrome 154 Update Fixes 32 Security Flaws Including Critical ANGLE Buffer Overflow (CVE-2026-102331)” (2026-09-30). Affected products concentrate in Google (5), Microsoft (5), Citrix (1), among 6 vendors in total.
Vulnerabilities (CVEs)
All 14 CVEs mapped to CWE-908, CISA KEV first, then by CVSS score.
- CVE-2026-85880 — CISA KEV · CVSS 7.8 high · published 2026-09-08
- CVE-2025-5777 — CISA KEV · CVSS 7.5 high · EPSS 62.2% · published 2025-06-17
- CVE-2024-50302 — CISA KEV · CVSS 5.5 medium · EPSS 0.8% · published 2024-11-19
- CVE-2026-40364 — CVSS 8.4 high · EPSS 0.1% · published 2026-05-12
- CVE-2026-94056 — CVSS 7.5 high · EPSS 0.2% · published 2026-09-19
- CVE-2026-57982 — CVSS 6.5 medium · EPSS 0.9% · published 2026-07-14
- CVE-2026-50497 — CVSS 6.5 medium · EPSS 0.8% · published 2026-07-14
- CVE-2026-55003 — CVSS 6.5 medium · EPSS 0.6% · published 2026-07-14
- CVE-2026-102307 — CVSS 4.7 medium · published 2026-09-29
- CVE-2026-102313 — CVSS 4.7 medium · published 2026-09-29
- CVE-2026-62377 — CVSS 4.3 medium · EPSS 0.4% · published 2026-08-18
- CVE-2026-102300 — CVSS 4.3 medium · published 2026-09-29
- CVE-2026-102303 — CVSS 4.3 medium · published 2026-09-29
- CVE-2026-102311 — CVSS 3.4 low · published 2026-09-29
Affected vendors
Threat activity
19 tracked threats cite CWE-908:
- Google Chrome 154 Update Fixes 32 Security Flaws Including Critical ANGLE Buffer Overflow (CVE-2026-102331)CRITICAL
- UTA0565 Chains Chrome and Windows Zero-Days (CVE-2026-85046, CVE-2026-87491, CVE-2026-85880) to Deploy CLEANGULP MalwareCRITICAL
- CISA Adds Two Citrix NetScaler Vulnerabilities (CVE-2026-88771, CVE-2026-88772) to KEV CatalogCRITICAL
- September 2026 Microsoft Patch Tuesday — Record 966+ Vulnerabilities with Two Actively Exploited Zero-Days (CVE-2026-81963, CVE-2026-85880) and Multiple Critical Wormable RCEsCRITICAL
- Microsoft September 2026 Patch Tuesday — 999 CVEs, 3 actively exploited zero-days (CVE-2026-85880, CVE-2026-81963, CVE-2026-85046)CRITICAL
- Serbian Authorities Deploy Pegasus and NoviSpy Spyware Against Journalists, Opposition Politicians, and Student ProtestersHIGH
- Anubis Ransomware Group Confirms Data Theft in Coca-Cola Fairlife Attack Tied to CitrixBleed 2 (CVE-2025-5777) Exploitation WaveCRITICAL
- Windows RDP Memory-Disclosure Vulnerabilities (CVE-2026-50445, CVE-2026-57982, CVE-2026-55003, CVE-2026-50497, CVE-2026-57979) — July 2026 Patch TuesdayMEDIUM
- F5 Patches Multiple NGINX Vulnerabilities: Heap Overflow, Memory Disclosure, and Use-After-Free (CVE-2026-42533, CVE-2026-60005, CVE-2026-56434)CRITICAL
- Microsoft July 2026 Patch Tuesday: Two Actively Exploited Zero-Days in AD FS and SharePoint (CVE-2026-56155, CVE-2026-56164)CRITICAL
- CitrixBleed 2 (CVE-2025-5777) Weaponized by Initial Access Broker for DragonForce Ransomware DeploymentCRITICAL
- CVE-2026-8037: Unauthenticated OS Command Injection in Progress Kemp LoadMaster via Uninitialized Heap in escape_quotes() (CVSS 9.6-9.8, Active Exploitation)CRITICAL
- CitrixBleed-Class NetScaler ADC/Gateway SAML AuthnRequest Memory Disclosure (CVE-2026-8451) Exploited Within 24 Hours of DisclosureCRITICAL
- Ransomware Groups Exploit Citrix Bleed 2 (CVE-2025-5777) and Kontron Driver BYOVD for Access and Privilege EscalationCRITICAL
- CVE-2026-8037: Pre-Auth Command Injection RCE in Progress Kemp LoadMaster via Uninitialized-Heap escape_quotes() Flaw on /accessv2CRITICAL
- Microsoft May 2026 Patch Tuesday — 137 CVEs, 31 Critical (16 RCE) Including CVE-2026-41089 Pre-Auth Netlogon Stack Overflow on Domain ControllersHIGH
- CitrixBleed 3 — CVE-2026-3055 & CVE-2026-4368 NetScaler ADC/Gateway Memory Overread and Session HijackCRITICAL
- CVE-2026-3055 & CVE-2026-4368: Citrix NetScaler ADC/Gateway Pre-Auth Memory Overread and Session MixupCRITICAL
- Citrix NetScaler Mass Reconnaissance Campaign via Residential ProxiesHIGH
Mitigations
- Implementation: Explicitly initialize the resource before use. If this is performed through an API function or standard procedure, follow all required steps.
- Implementation: Pay close attention to complex conditionals that affect initialization, since some branches might not perform the initialization.
- Implementation: Avoid race conditions (CWE-362) during initialization routines.
- Build and Compilation: Run or compile the product with settings that generate warnings about uninitialized variables or data.
Source: MITRE CWE, potential mitigations.
Detection methods (MITRE CWE)
- Automated Static Analysis: Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)
Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.