Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-1390 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 17 | 13 | 1 |
▂▁▁▂▁▁▁▁▁▁▄▁▁▁▁▁▁▁▁▁▁▁▁▇▄█▄
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 4 · 2026-06 2 · 2026-07 5 · 2026-08 2
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-55040 | 9.1 | 92.1 | KEV | Microsoft SharePoint Server Security Feature Bypass Vulnerability |
| CVE-2025-27740 | 8.8 | 87.4 | — | Active Directory Certificate Services Elevation of Privilege Vulnerability |
| CVE-2024-38239 | 7.2 | 76.0 | — | Windows Kerberos Elevation of Privilege Vulnerability |
| CVE-2025-26635 | 6.5 | 70.5 | — | Windows Hello Security Feature Bypass Vulnerability |
| CVE-2024-35248 | 7.3 | 58.3 | — | Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability |
| CVE-2026-6274 | 9.8 | 38.2 | — | Authentication Bypass in DTS Electronics' Redline WR3200 |
| CVE-2026-50756 | 7.5 | 30.1 | — | — |
| CVE-2026-59135 | 5.5 | 24.9 | — | Microsoft Windows Search Component Information Disclosure Vulnerability |
| CVE-2026-59554 | 7.5 | 22.0 | — | WordPress Ziina plugin <= 1.2.21 - Broken Authentication vulnerability |
| CVE-2026-0274 | 8.1 | 21.1 | — | Cortex XSOAR: Improper Validation of Credentials in CommvaultSecurityIQ integration |
| CVE-2026-68067 | 9.3 | 21.0 | — | Mira Hormone Monitor, Mira Android App Weak Authentication |
| CVE-2026-40417 | 7.8 | 19.7 | — | Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability |
| CVE-2026-57352 | 4.8 | 10.7 | — | WordPress ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce plugin <= 2… |
| CVE-2026-44237 | 7.6 | 10.3 | — | FreePBX: Authenticated Access can lead to Subsequent OAuth2 Authentication Bypass in AP… |
| CVE-2026-10714 | 8.8 | 1.7 | — | Rockwell Automation FactoryTalk® Services Platform FTSP - Weak Authentication via JWT V… |
| CVE-2026-49323 | 4.1 | 1.3 | — | Indian Scout Bobber 2025 WCM-to-ECM weak authentication |
| CVE-2026-49322 | 4.1 | 1.1 | — | Indian Scout Bobber 2025 Infotainment-to-WCM weak authentication allows recovery of use… |
| Vendor | CVEs |
|---|---|
| microsoft | 7 |
| indian motorcycle | 2 |
| dts electronics industry and trade ltd. co | 1 |
| freepbx | 1 |
| palo alto networks | 1 |
| quanovate tech inc. (operating as mira / mira care) | 1 |
| rockwell automation | 1 |
| villatheme | 1 |
| ziina | 1 |