# wekan vulnerabilities & exploitation

> As of 2026-10-05, Threadlinqs tracks 10 wekan CVEs, 0 in the CISA Known Exploited Vulnerabilities catalog, linked to 0 tracked threat campaigns.

**Data as of:** 2026-10-05

## Exploitation timeline

Threadlinqs has recorded 10 wekan CVEs published between 2026-07-15 and 2026-07-15. The busiest month was 2026-07 (10 new CVEs). None of them is listed in CISA KEV yet.

## Most exploited vulnerabilities

Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 10 of 10 tracked wekan CVEs.

- [CVE-2026-52891](https://intel.threadlinqs.com/cve/CVE-2026-52891) — CRITICAL 9.9 · EPSS 0.4% · 2026-07-15
- [CVE-2026-55652](https://intel.threadlinqs.com/cve/CVE-2026-55652) — CRITICAL 9.8 · EPSS 0.4% · 2026-07-15
- [CVE-2026-52890](https://intel.threadlinqs.com/cve/CVE-2026-52890) — HIGH 7.1 · EPSS 0.3% · 2026-07-15
- [CVE-2026-53446](https://intel.threadlinqs.com/cve/CVE-2026-53446) — MEDIUM 6.2 · EPSS 0.3% · 2026-07-15
- [CVE-2026-52892](https://intel.threadlinqs.com/cve/CVE-2026-52892) — MEDIUM 6.5 · EPSS 0.3% · 2026-07-15
- [CVE-2026-55234](https://intel.threadlinqs.com/cve/CVE-2026-55234) — HIGH 8.5 · EPSS 0.2% · 2026-07-15
- [CVE-2026-53444](https://intel.threadlinqs.com/cve/CVE-2026-53444) — HIGH 7.6 · EPSS 0.2% · 2026-07-15
- [CVE-2026-53445](https://intel.threadlinqs.com/cve/CVE-2026-53445) — HIGH 7.1 · EPSS 0.2% · 2026-07-15
- [CVE-2026-53447](https://intel.threadlinqs.com/cve/CVE-2026-53447) — MEDIUM 6.5 · EPSS 0.2% · 2026-07-15
- [CVE-2026-52893](https://intel.threadlinqs.com/cve/CVE-2026-52893) — CRITICAL 9.2 · 2026-07-15

## Products affected

Threadlinqs normalises CPE and CNA product records across all 10 CVEs; 1 distinct wekan product is affected. The most frequently affected:

- wekan — 10 CVEs

## Threat activity

No tracked threat campaign references wekan products or CVEs yet. Vulnerability records are still monitored for exploitation and linked as campaigns are ingested.

## How to prioritise wekan patching

This order follows the data Threadlinqs holds for wekan, not a generic severity checklist:

- No wekan CVE is in CISA KEV yet, so rank by exploit probability instead.
- Outside KEV, the highest EPSS scores are [CVE-2026-52891](https://intel.threadlinqs.com/cve/CVE-2026-52891) (0.4%), [CVE-2026-55652](https://intel.threadlinqs.com/cve/CVE-2026-55652) (0.4%), [CVE-2026-52890](https://intel.threadlinqs.com/cve/CVE-2026-52890) (0.3%).
- 3 CVEs score Critical and 4 High on CVSS v3 (maximum 9.9, average 7.8); sequence these after KEV and high-EPSS items.

## About this data

Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.

Canonical: https://intel.threadlinqs.com/vendors/wekan
All vendors: https://intel.threadlinqs.com/vendors
Full detection coverage and IOCs via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
