Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-807
Weakness type CWE-807 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 47 | 46 | 3 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▂▂▂▅█▂
2025-11 0 · 2025-12 0 · 2026-01 2 · 2026-02 1 · 2026-03 0 · 2026-04 1 · 2026-05 2 · 2026-06 4 · 2026-07 3 · 2026-08 10 · 2026-09 20 · 2026-10 3
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-21509 | 7.8 | 99.4 | KEV | Microsoft Office Security Feature Bypass Vulnerability |
| CVE-2026-34486 | 7.5 | 93.6 | KEV | Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor |
| CVE-2026-21514 | 7.8 | 74.6 | KEV | Microsoft Word Security Feature Bypass Vulnerability |
| CVE-2026-82533 | 9.4 | 67.2 | — | DeepSeek Harness < 0.1.2-alpha.1 Authentication Bypass via Host Header Spoofing |
| CVE-2026-20849 | 7.5 | 62.4 | — | Windows Kerberos Elevation of Privilege Vulnerability |
| CVE-2026-56681 | 7.3 | 60.5 | — | 9Router: Authentication Bypass in Public LLM API via Spoofable X-9r-Real-Ip Header |
| CVE-2026-64827 | 9.3 | 56.1 | — | Telenia TVox 26.5.3 Authentication Bypass via set_env.php |
| CVE-2026-84474 | 9.9 | 55.1 | — | Automation-controller: automation-controller-container: automation-controller: view_job… |
| CVE-2026-87858 | 7.2 | 54.4 | — | Temporal Server completion callback source header can direct attacker-chosen requests t… |
| CVE-2026-63041 | 5.3 | 50.8 | — | Apache APISIX: attach-consumer-label does not strip client-supplied consumer-label headers |
| CVE-2026-54730 | 8.6 | 50.7 | — | authentik: Authentication Flow Bypass via Unguarded challenge_valid() in AuthenticatorE… |
| CVE-2026-66768 | 9.0 | 47.6 | — | Improper Access Control in SAP NetWeaver (SAP GUI for Java) |
| CVE-2026-59157 | 6.5 | 46.6 | — | webhookd: Unrestricted HTTP Header to Shell Variable Injection |
| CVE-2026-86863 | 9.3 | 46.0 | — | pgAdmin 4: Authentication bypass via a client-controlled identity header in Webserver a… |
| CVE-2026-85751 | 9.8 | 44.5 | — | Mailu: Authentication bypass in header-based proxy authentication via spoofable `X-Forw… |
| CVE-2026-43935 | 8.1 | 43.9 | — | e107: Host Header Injection in e107 password reset enables phishing |
| CVE-2026-94606 | 8.9 | 39.9 | — | authentik: MFA Bypass via State Confusion / Parameter Injection in AuthenticatorEmailStage |
| CVE-2026-81179 | 8.1 | 39.2 | — | SysReptor: Host header injection might allow account takeover |
| CVE-2026-56682 | 5.3 | 38.3 | — | 9Router: Login Brute-Force Lockout Bypass via Spoofable X-9r-Real-Ip Header |
| CVE-2026-79700 | 6.9 | 37.2 | — | Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass via Request-Controll… |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| microsoft | 4 |
| apache | 2 |
| decolua | 2 |
| goauthentik | 2 |
| joomshaper.com | 2 |
| mongodb | 2 |
| red hat | 2 |
| sap_se | 2 |
| traefik | 2 |
| agentverus | 1 |
| deepseek | 1 |
| deepseek-ai | 1 |
| e107inc | 1 |
| eclipse foundation | 1 |
| genians | 1 |