Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-267
Weakness type CWE-267 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 9 | 8 | 1 |
Monthly trend
▃▁▁▁▁▁▁▁▆▁▁█▆▃
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 2 · 2026-06 0 · 2026-07 0 · 2026-08 3 · 2026-09 2 · 2026-10 1
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2025-41244 | 7.8 | 94.8 | KEV | VMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulner… |
| CVE-2026-18951 | 8.8 | 58.8 | — | Odh-training-operator-rhel9: [trainer v2 security] trn-02: rhoai overlay aggregates tra… |
| CVE-2026-10090 | 9.0 | 45.6 | — | Multicluster-operators-subscription: multicluster-operators-subscription: namespace edi… |
| CVE-2026-6816 | 5.1 | 30.5 | — | TFA Basic Plugins - Access Bypass |
| CVE-2026-9560 | 9.4 | 29.3 | — | — |
| CVE-2026-96659 | 9.1 | 23.0 | — | Foreman: excessive permissions for viewer role on preview |
| CVE-2025-36255 | 8.8 | 14.2 | — | DS8900F and DS8A00 Privilege Escalation |
| CVE-2026-81161 | 3.3 | 9.9 | — | Content Moderation Notifications - Moderately critical - Access bypass - SA-CONTRIB-202… |
| CVE-2026-18858 | 5.5 | 0.7 | — | IBM i is Affected By Obtaining Sensitive Information Vulnerability in OpenSSH [] |