CWE-287 - Improper Authentication - Cwe

Threat entity extracted from intelligence sources

Frequency
729
occurrences
First Seen
April 16, 2026
Last Seen
July 18, 2026

CWE-287 - Improper Authentication is a cwe tracked across 50 threat clusters and 729 intelligence report mentions on ThreatCluster. First observed April 16, 2026; most recent activity July 18, 2026.

Related Threat Clusters

Recent Intelligence Reports

  • Garante per la protezione dei dati personali's Newsletter No. 549 — www.garanteprivacy.it · July 18, 2026
  • Reference 1 — support.broadcom.com · July 18, 2026
  • Google’s Gemini lets strangers send messages from your locked Android phone — Grahamcluley · July 17, 2026
  • Google fixing Android lock screen bug that lets Gemini send SMS without a PIN — Theregister · July 17, 2026
  • Unauthenticated RCE in WordPress core (wp2shell). Patch now! — Aikido.Dev · July 17, 2026
  • VMware Avi Load Balancer: Critical vulnerability allows bypassing login — Heise.De · July 17, 2026
  • Shark robot vacuums vulnerable to remote command execution — Feeds.Feedburner · July 16, 2026
  • Ubuntu 26.04 Authlib Important JWT Bypass and CSRF Vulnerities USN-8557 — Linuxsecurity · July 16, 2026

CVSS v3.1 Breakdown