Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-403
Weakness type CWE-403 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 4 | 3 | 0 |
Monthly trend
█▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁███▁▁
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 0 · 2026-06 1 · 2026-07 1 · 2026-08 1 · 2026-09 0 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-21626 | 8.6 | 97.2 | — | runc container breakout through process.cwd trickery and leaked fds |
| CVE-2026-16526 | 8.8 | 45.2 | — | Pcp: pcp: privilege escalation to root via linux_sockets pmda vulnerability |
| CVE-2026-33263 | 4.3 | 44.3 | — | — |
| CVE-2026-12296 | 9.6 | 31.1 | — | Sandbox escape in the Security: Process Sandboxing component |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| mozilla | 1 |
| open-xchange | 1 |
| opencontainers | 1 |
| red hat | 1 |