Glossary
CWE
Common Weakness Enumeration — A community-developed, categorized list of common software and hardware weakness types, such as buffer overflow or SQL injection, maintained by MITRE. Where a CVE identifies a specific vulnerability instance, a CWE identifies the underlying class of flaw that caused it.
Recent coverage mentioning CWE
CVE-2026-85880: Windows ALPC Heap Overflow Exploited
CISA confirms active exploitation of CVE-2026-85880, a heap-based buffer overflow in Microsoft Windows ALPC leading to local privilege escalation.
N-able N-central RCE via CVE-2026-86218 Under Active Exploitation
CISA confirms active exploitation of CVE-2026-86218, a pre-authentication remote code execution flaw in N-able N-central, urging immediate mitigation.
CVE-2026-81963: Windows Update Stack Privilege Escalation
CISA adds CVE-2026-81963 to the KEV catalog after confirming active exploitation of a Windows Update Stack privilege escalation flaw.
CVE-2026-9586: Sangoma Switchvox RCE via SQL Injection
Sangoma Switchvox is affected by CVE-2026-9586, an unauthenticated remote SQL injection vulnerability enabling RCE, with active exploitation confirmed.
CVE-2026-49869: Kestra OSS OS Command Injection Exploited
CISA has added CVE-2026-49869, an OS command injection in Kestra OSS, to its KEV catalog, confirming active exploitation by unauthenticated attackers.
CVE-2026-59822: BerriAI LiteLLM Authentication Bypass
BerriAI LiteLLM is vulnerable to an improper authentication flaw (CVE-2026-59822) actively exploited to bypass authentication.
Advertisement