# CWE-908: Use of Uninitialized Resource

**Likelihood of exploit:** Medium · **KEV-linked**

> As of 2026-10-05, CWE-908 (Use of Uninitialized Resource) underlies 14 CVEs tracked by Threadlinqs, 3 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 19 tracked threats. MITRE rates its likelihood of exploit as Medium.

**Last updated:** 2026-10-05

## What is CWE-908?

The product uses or accesses a resource that has not been initialized.

When a resource has not been properly initialized, the product may behave unexpectedly. This may lead to a crash or invalid memory access, but the consequences vary depending on the type of resource and how it is used within the product.

CWE-908 is a base-level weakness in MITRE’s Common Weakness Enumeration, with a MITRE likelihood of exploit of Medium. Applicable platforms: Not Language-Specific.

_Source: [MITRE CWE](https://cwe.mitre.org/data/definitions/908.html) (CWE-908 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data._

## Consequences

- **Confidentiality** — Read Memory, Read Application Data. When reusing a resource such as memory or a program variable, the original contents of that resource may not be cleared before it is sent to an untrusted party.
- **Availability** — DoS: Crash, Exit, or Restart. The uninitialized resource may contain values that cause program flow to change in ways that the programmer did not intend.

_Source: MITRE CWE, common consequences._

## How CWE-908 is exploited in the wild

Threadlinqs maps 14 CVEs to CWE-908, published between 2024-11-19 and 2026-09-29. 3 are listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild, and 1 is tied to ransomware campaigns. By CVSS v3 severity the set splits into 4 high, 9 medium, 1 low. The highest EPSS score in the set is 62.2% (CVE-2025-5777), the modelled probability of exploitation in the next 30 days. 19 tracked threats reference CWE-908 directly or through a CVE it covers; the most recent is “Google Chrome 154 Update Fixes 32 Security Flaws Including Critical ANGLE Buffer Overflow (CVE-2026-102331)” (2026-09-30). Affected products concentrate in Google (5), Microsoft (5), Citrix (1), among 6 vendors in total.

## Vulnerabilities (CVEs)

All 14 CVEs mapped to CWE-908, CISA KEV first, then by CVSS score.

- [CVE-2026-85880](https://intel.threadlinqs.com/cve/CVE-2026-85880) — CISA KEV · CVSS 7.8 high · published 2026-09-08
- [CVE-2025-5777](https://intel.threadlinqs.com/cve/CVE-2025-5777) — CISA KEV · CVSS 7.5 high · EPSS 62.2% · published 2025-06-17
- [CVE-2024-50302](https://intel.threadlinqs.com/cve/CVE-2024-50302) — CISA KEV · CVSS 5.5 medium · EPSS 0.8% · published 2024-11-19
- [CVE-2026-40364](https://intel.threadlinqs.com/cve/CVE-2026-40364) — CVSS 8.4 high · EPSS 0.1% · published 2026-05-12
- [CVE-2026-94056](https://intel.threadlinqs.com/cve/CVE-2026-94056) — CVSS 7.5 high · EPSS 0.2% · published 2026-09-19
- [CVE-2026-57982](https://intel.threadlinqs.com/cve/CVE-2026-57982) — CVSS 6.5 medium · EPSS 0.9% · published 2026-07-14
- [CVE-2026-50497](https://intel.threadlinqs.com/cve/CVE-2026-50497) — CVSS 6.5 medium · EPSS 0.8% · published 2026-07-14
- [CVE-2026-55003](https://intel.threadlinqs.com/cve/CVE-2026-55003) — CVSS 6.5 medium · EPSS 0.6% · published 2026-07-14
- [CVE-2026-102307](https://intel.threadlinqs.com/cve/CVE-2026-102307) — CVSS 4.7 medium · published 2026-09-29
- [CVE-2026-102313](https://intel.threadlinqs.com/cve/CVE-2026-102313) — CVSS 4.7 medium · published 2026-09-29
- [CVE-2026-62377](https://intel.threadlinqs.com/cve/CVE-2026-62377) — CVSS 4.3 medium · EPSS 0.4% · published 2026-08-18
- [CVE-2026-102300](https://intel.threadlinqs.com/cve/CVE-2026-102300) — CVSS 4.3 medium · published 2026-09-29
- [CVE-2026-102303](https://intel.threadlinqs.com/cve/CVE-2026-102303) — CVSS 4.3 medium · published 2026-09-29
- [CVE-2026-102311](https://intel.threadlinqs.com/cve/CVE-2026-102311) — CVSS 3.4 low · published 2026-09-29

## Affected vendors

- [Google](https://intel.threadlinqs.com/vendors/google) — 5 CVEs
- [Microsoft](https://intel.threadlinqs.com/vendors/microsoft) — 5 CVEs
- [Citrix](https://intel.threadlinqs.com/vendors/citrix) — 1 CVE
- [Exim](https://intel.threadlinqs.com/vendors/exim) — 1 CVE
- [Linux](https://intel.threadlinqs.com/vendors/linux) — 1 CVE
- **strukturag** — 1 CVE

## Threat activity

19 tracked threats cite CWE-908:

- [Google Chrome 154 Update Fixes 32 Security Flaws Including Critical ANGLE Buffer Overflow (CVE-2026-102331)](https://intel.threadlinqs.com/threat/TL-2026-2803) — CRITICAL · 2026-09-30
- [UTA0565 Chains Chrome and Windows Zero-Days (CVE-2026-85046, CVE-2026-87491, CVE-2026-85880) to Deploy CLEANGULP Malware](https://intel.threadlinqs.com/threat/TL-2026-2681) — CRITICAL · 2026-09-27
- [CISA Adds Two Citrix NetScaler Vulnerabilities (CVE-2026-88771, CVE-2026-88772) to KEV Catalog](https://intel.threadlinqs.com/threat/TL-2026-2711) — CRITICAL · 2026-09-27
- [September 2026 Microsoft Patch Tuesday — Record 966+ Vulnerabilities with Two Actively Exploited Zero-Days (CVE-2026-81963, CVE-2026-85880) and Multiple Critical Wormable RCEs](https://intel.threadlinqs.com/threat/TL-2026-2398) — CRITICAL · 2026-09-08
- [Microsoft September 2026 Patch Tuesday — 999 CVEs, 3 actively exploited zero-days (CVE-2026-85880, CVE-2026-81963, CVE-2026-85046)](https://intel.threadlinqs.com/threat/TL-2026-2407) — CRITICAL · 2026-09-08
- [Serbian Authorities Deploy Pegasus and NoviSpy Spyware Against Journalists, Opposition Politicians, and Student Protesters](https://intel.threadlinqs.com/threat/TL-2026-2316) — HIGH · 2026-09-03
- [Anubis Ransomware Group Confirms Data Theft in Coca-Cola Fairlife Attack Tied to CitrixBleed 2 (CVE-2025-5777) Exploitation Wave](https://intel.threadlinqs.com/threat/TL-2026-1729) — CRITICAL · 2026-07-27
- [Windows RDP Memory-Disclosure Vulnerabilities (CVE-2026-50445, CVE-2026-57982, CVE-2026-55003, CVE-2026-50497, CVE-2026-57979) — July 2026 Patch Tuesday](https://intel.threadlinqs.com/threat/TL-2026-1370) — MEDIUM · 2026-07-15
- [F5 Patches Multiple NGINX Vulnerabilities: Heap Overflow, Memory Disclosure, and Use-After-Free (CVE-2026-42533, CVE-2026-60005, CVE-2026-56434)](https://intel.threadlinqs.com/threat/TL-2026-1391) — CRITICAL · 2026-07-15
- [Microsoft July 2026 Patch Tuesday: Two Actively Exploited Zero-Days in AD FS and SharePoint (CVE-2026-56155, CVE-2026-56164)](https://intel.threadlinqs.com/threat/TL-2026-1336) — CRITICAL · 2026-07-14
- [CitrixBleed 2 (CVE-2025-5777) Weaponized by Initial Access Broker for DragonForce Ransomware Deployment](https://intel.threadlinqs.com/threat/TL-2026-1150) — CRITICAL · 2026-07-09
- [CVE-2026-8037: Unauthenticated OS Command Injection in Progress Kemp LoadMaster via Uninitialized Heap in escape_quotes() (CVSS 9.6-9.8, Active Exploitation)](https://intel.threadlinqs.com/threat/TL-2026-1067) — CRITICAL · 2026-07-02
- [CitrixBleed-Class NetScaler ADC/Gateway SAML AuthnRequest Memory Disclosure (CVE-2026-8451) Exploited Within 24 Hours of Disclosure](https://intel.threadlinqs.com/threat/TL-2026-1078) — CRITICAL · 2026-07-02
- [Ransomware Groups Exploit Citrix Bleed 2 (CVE-2025-5777) and Kontron Driver BYOVD for Access and Privilege Escalation](https://intel.threadlinqs.com/threat/TL-2026-1086) — CRITICAL · 2026-07-02
- [CVE-2026-8037: Pre-Auth Command Injection RCE in Progress Kemp LoadMaster via Uninitialized-Heap escape_quotes() Flaw on /accessv2](https://intel.threadlinqs.com/threat/TL-2026-1045) — CRITICAL · 2026-07-01
- [Microsoft May 2026 Patch Tuesday — 137 CVEs, 31 Critical (16 RCE) Including CVE-2026-41089 Pre-Auth Netlogon Stack Overflow on Domain Controllers](https://intel.threadlinqs.com/threat/TL-2026-0504) — HIGH · 2026-05-12
- [CitrixBleed 3 — CVE-2026-3055 & CVE-2026-4368 NetScaler ADC/Gateway Memory Overread and Session Hijack](https://intel.threadlinqs.com/threat/TL-2026-0384) — CRITICAL · 2026-04-17
- [CVE-2026-3055 & CVE-2026-4368: Citrix NetScaler ADC/Gateway Pre-Auth Memory Overread and Session Mixup](https://intel.threadlinqs.com/threat/TL-2026-0294) — CRITICAL · 2026-03-28
- [Citrix NetScaler Mass Reconnaissance Campaign via Residential Proxies](https://intel.threadlinqs.com/threat/TL-2026-0061) — HIGH · 2026-02-03

## Mitigations

- **Implementation**: Explicitly initialize the resource before use. If this is performed through an API function or standard procedure, follow all required steps.
- **Implementation**: Pay close attention to complex conditionals that affect initialization, since some branches might not perform the initialization.
- **Implementation**: Avoid race conditions (CWE-362) during initialization routines.
- **Build and Compilation**: Run or compile the product with settings that generate warnings about uninitialized variables or data.

_Source: MITRE CWE, potential mitigations._

## Detection methods (MITRE CWE)

- **Automated Static Analysis**: Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)

_Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher._

## Related weaknesses

- CWE-665 Improper Initialization

Canonical: https://intel.threadlinqs.com/cwe/CWE-908
Source definition: https://cwe.mitre.org/data/definitions/908.html
Detection rules and IOCs for threats exploiting CWE-908 via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
