Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-666
Weakness type CWE-666 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 3 | 3 | 0 |
Monthly trend
▅█▁
2026-08 1 · 2026-09 2 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-68930 | 6.5 | 29.4 | — | Russh: Channel-scoped server callbacks can be reached without an open channel |
| CVE-2026-16148 | 4.6 | 5.4 | — | Kernel panic in the it82xx2 USB device controller driver via re-initialization of a bus… |
| CVE-2026-15460 | 5.4 | 4.4 | — | Missing channel-state validation in Zephyr Bluetooth Classic L2CAP receive path |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| zephyrproject | 2 |
| eugeny | 1 |