Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-1390
Weakness type CWE-1390 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 28 | 24 | 1 |
Monthly trend
▂▁▁▂▁▁▁▁▁▁▃▁▁▁▁▁▁▁▁▁▁▁▁▅▃▆▆█▂
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 4 · 2026-06 2 · 2026-07 5 · 2026-08 5 · 2026-09 7 · 2026-10 1
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-55040 | 9.1 | 97.1 | KEV | Microsoft SharePoint Server Security Feature Bypass Vulnerability |
| CVE-2025-27740 | 8.8 | 88.5 | — | Active Directory Certificate Services Elevation of Privilege Vulnerability |
| CVE-2024-38239 | 7.2 | 77.0 | — | Windows Kerberos Elevation of Privilege Vulnerability |
| CVE-2025-26635 | 6.5 | 72.9 | — | Windows Hello Security Feature Bypass Vulnerability |
| CVE-2026-65098 | 9.8 | 61.2 | — | — |
| CVE-2024-35248 | 7.3 | 60.0 | — | Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability |
| CVE-2026-73025 | 9.8 | 58.3 | — | Windows iSCSI Security Feature Bypass Vulnerability |
| CVE-2026-62895 | 8.8 | 55.6 | — | Azure Arc SQL Server Extension Elevation of Privilege Vulnerability |
| CVE-2026-77483 | 8.8 | 54.3 | — | SQL Server Elevation of Privilege Vulnerability |
| CVE-2026-6274 | 9.8 | 49.0 | — | Authentication Bypass in DTS Electronics' Redline WR3200 |
| CVE-2026-44476 | 6.3 | 44.9 | — | Doorkeeper OpenID Connect: Dynamic Client Registration feature creates public clients w… |
| CVE-2026-73819 | 9.3 | 42.7 | — | Ebyte NA111-M Weak Authentication |
| CVE-2026-68067 | 9.3 | 41.5 | — | Mira Hormone Monitor, Mira Android App Weak Authentication |
| CVE-2026-50756 | 7.5 | 41.1 | — | — |
| CVE-2026-96940 | 8.8 | 40.4 | — | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2026-59554 | 7.5 | 34.7 | — | WordPress Ziina plugin <= 1.2.21 - Broken Authentication vulnerability |
| CVE-2026-92289 | 9.1 | 31.1 | — | Lemonldap::NG::Portal versions from 2.23.0 before 2.23.4 for Perl allow a PKCE bypass f… |
| CVE-2026-92288 | 9.1 | 28.5 | — | Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before 2.23.4 for… |
| CVE-2026-44237 | 7.6 | 26.3 | — | FreePBX: Authenticated Access can lead to Subsequent OAuth2 Authentication Bypass in AP… |
| CVE-2026-59135 | 5.5 | 26.3 | — | Microsoft Windows Search Component Information Disclosure Vulnerability |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| microsoft | 11 |
| indian motorcycle | 2 |
| berriai | 1 |
| doorkeeper-gem | 1 |
| dts electronics industry and trade ltd. co | 1 |
| ebyte | 1 |
| freepbx | 1 |
| gitroomhq | 1 |
| nvidia | 1 |
| palo alto networks | 1 |
| quanovate tech inc. (operating as mira / mira care) | 1 |
| rockwell automation | 1 |
| villatheme | 1 |
| ziina | 1 |