Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-1394
Weakness type CWE-1394 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 3 | 3 | 0 |
Monthly trend
██▁█
2026-07 1 · 2026-08 1 · 2026-09 0 · 2026-10 1
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-75870 | 9.1 | 40.5 | — | Punk versions before 0.18 for Perl allow session cookie forgery via an empty default HM… |
| CVE-2026-54887 | 6.3 | 14.2 | — | DTLS server cookie bypass during startup window due to empty initial cookie secret |
| CVE-2026-107177 | 7.4 | — | — | Express Gateway through 1.16.11 Hardcoded Default cipherKey Exposes OAuth Tokens |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| erlang | 1 |
| expressgateway | 1 |