Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-327
Weakness type CWE-327 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 77 | 76 | 0 |
Monthly trend
▁▁▁▁▁▁▁▂█▃▄▅▁
2025-11 0 · 2025-12 0 · 2026-01 1 · 2026-02 0 · 2026-03 0 · 2026-04 2 · 2026-05 4 · 2026-06 29 · 2026-07 9 · 2026-08 14 · 2026-09 17 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-48386 | 7.5 | 60.3 | — | ColdFusion | Use of a Broken or Risky Cryptographic Algorithm (CWE-327) |
| CVE-2026-5588 | 6.3 | 51.0 | — | PKIX draft CompositeVerifier accepts empty signature sequence as valid. |
| CVE-2026-20833 | 5.5 | 43.5 | — | Windows Kerberos Information Disclosure Vulnerability |
| CVE-2026-69382 | 5.9 | 38.5 | — | Microsoft Exchange Server Information Disclosure Vulnerability |
| CVE-2026-50086 | 9.8 | 36.1 | — | Aqara unauthenticated AES oracle |
| CVE-2026-76133 | 9.3 | 31.6 | — | Ebyte NA111-M Use of a Broken or Risky Cryptographic Algorithm |
| CVE-2026-77151 | 6.3 | 28.3 | — | lin-snow Ech0 crypto.go MD5Encrypt risky encryption |
| CVE-2026-66407 | 7.7 | 23.8 | — | — |
| CVE-2026-9261 | 7.6 | 23.0 | — | — |
| CVE-2025-14813 | 9.3 | 22.7 | — | GOSTCTR implementation unable to process more than 255 blocks correctly |
| CVE-2026-45701 | 6.9 | 22.6 | — | Sulu: Weak Cryptographical usage for API Key generation and Reset Tokens |
| CVE-2026-13510 | 2.9 | 21.6 | — | SimStudioAI sim Password Protection deployment.ts weak hash |
| CVE-2026-14738 | 2.9 | 21.6 | — | exo-explore exo Vision Feature Cache vision.py _image_cache_key weak hash |
| CVE-2026-44053 | 7.4 | 19.8 | — | Weak cryptography in DHCAST128 UAM |
| CVE-2026-46395 | 9.3 | 19.2 | — | HAX CMS Vulnerable to Private Key Disclosure via Broken HMAC Implementation |
| CVE-2026-39944 | 8.8 | 19.1 | — | Ceph: CephX AES Authentication error |
| CVE-2026-13482 | 2.9 | 18.7 | — | skypilot-org skypilot User ID server.py username.encode weak hash |
| CVE-2026-63761 | 5.3 | 18.4 | — | SurrealDB before 3.1.0 Algorithm Downgrade via ES512 |
| CVE-2026-74888 | 8.7 | 17.8 | — | openssl_encrypt before 1.4.0 Non-Standard PBKDF2 Key Derivation |
| CVE-2026-27871 | 2.9 | 17.3 | — | TL280 |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| ibm | 10 |
| dell | 4 |
| ceph | 2 |
| hcl software | 2 |
| indian motorcycle | 2 |
| legion of the bouncy castle | 2 |
| microsoft | 2 |
| oberon microsystems | 2 |
| wolfssl | 2 |
| yoanbernabeu | 2 |
| admin by request (abr) | 1 |
| adobe | 1 |
| andritz | 1 |
| aqara | 1 |
| aveva | 1 |