Reference page — cumulative record through Monday, October 5, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-565
Weakness type CWE-565 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 8 | 8 | 1 |
Monthly trend
▅▃▁▃█▁
2026-05 2 · 2026-06 1 · 2026-07 0 · 2026-08 1 · 2026-09 4 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-0257 | 7.8 | 99.9 | KEV | PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities |
| CVE-2026-76186 | 9.1 | 55.5 | — | Apache Airflow Keycloak provider: Keycloak token cookies not bound to Airflow session i… |
| CVE-2026-85181 | 9.3 | 51.7 | — | CAT through 3.1.0 Session Cookie Forgery via Unkeyed hashCode Checksum |
| CVE-2026-75757 | 8.3 | 42.4 | — | AshAdmin cookie reader matches names by substring, enabling actor/session shadowing fro… |
| CVE-2026-69215 | 6.8 | 41.0 | — | Http4s: CookieJar middleware matches by substring, leaking cookies cross-origin |
| CVE-2026-53871 | 8.6 | 40.8 | — | Hermes WebUI < 0.51.368 - Profile-Scoped Authorization Bypass via Forged hermes_profile… |
| CVE-2026-69214 | 6.8 | 31.3 | — | Http4s: CookieJar middleware accepts arbitrary Set-Cookie domain |
| CVE-2026-8337 | 6.3 | 23.2 | — | Concrete CMS 9.5.0 and below is vulnerable to IDOR in surveys when sites are running co… |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| http4s | 2 |
| apache | 1 |
| ash-project | 1 |
| concrete cms | 1 |
| dianping | 1 |
| nesquena | 1 |
| palo alto networks | 1 |