Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

macOS Flaw Lets Standard Users Disable EDR and MDM

June 26, 2026

Crypto Clipper Campaign Abuses Fake Reviews, AI Narrators, and VirusTotal Comments

June 26, 2026

Major Increase in Ransomware Attacks Targeting Europe, Warns Report

June 26, 2026
Facebook X (Twitter) Instagram
Friday, June 26
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»Cyber Security»Top 25 Most Dangerous Software Weaknesses of 2025 Revealed
Cyber Security

Top 25 Most Dangerous Software Weaknesses of 2025 Revealed

Team-CWDBy Team-CWDDecember 15, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


The MITRE Corporation has released the 25 most dangerous software “weaknesses” in a new list that will help inform developers, network defenders and procurement teams.

The annual CWE Top 25 list was this year compiled from the weaknesses (CWEs) behind 39,080 CVEs.

“Uncovering the root causes of these vulnerabilities serves as a powerful guide for investments, policies, and practices to prevent these vulnerabilities from occurring in the first place – benefiting both industry and government stakeholders,” MITRE claimed.

Top of the list once again was cross-site scripting (XSS), while SQL injection moved up one place to second and cross-site request forgery moved up one to third. Use-after-free (in eighth place) and code injection (tenth) both moved up one from last year.

Among the top 10, out-of-bounds write (fifth), path traversal (sixth), out-of-bounds read (eighth) and OS command injection (ninth) all dropped down from their rankings last year.

Read more on CWEs: MITRE Unveils Top 25 Most Critical Software Flaws

The rankings are calculated by scoring each weakness based on its severity and the frequency of in-the-wild exploits.

This year, there were new entries for classic buffer overflow, stack-based buffer overflow, heap-based buffer overflow, improper access control, authorization bypass through user-controlled key, and allocation of resources without limits or throttling.

However, AppOmni CSO, Cory Michal, argued that there should have been a place on the Top 25 for “insufficiently protected credentials,” given how dangerous weak credential handling is.

“When major SaaS integration providers like Commvault, Salesloft/Drift and Gainsight are breached and attackers walk away with OAuth2 tokens, those ‘credentials’ become a skeleton key into thousands of downstream SaaS tenants,” he explained.

“We’re seeing adversaries use those stolen tokens to access CRM and collaboration data without ever touching a user’s password, and I’d expect that pattern, and therefore CWE-522’s real-world impact to keep growing in 2026.”

That said, the new list highlights how identity, authorization and access control issues are now very much front and center for security teams.

“When weaknesses like missing authentication, improper access control and authorization bypass, all climb or enter the Top 25, it’s a signal that attackers are consistently succeeding at finding and exploiting gaps in authentication and authorization logic,” Michal said.

“In today’s SaaS and AI world, where apps are interconnected by APIs and integrations, these weaknesses quickly turn into lateral movement, data exposure and realized risk.”



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleAsahi to Launch Cybersecurity Overhaul After Crippling Cyber-Attack
Next Article Critical React2Shell Flaw Added to CISA KEV After Confirmed Active Exploitation
Team-CWD
  • Website

Related Posts

Cyber Security

Major Increase in Ransomware Attacks Targeting Europe, Warns Report

June 26, 2026
Cyber Security

Interview: Shopify CISO Andrew Dunbar on Securing an E-Commerce Giant

June 26, 2026
Cyber Security

Cisco Vulnerability Exploited Months Before Disclosure, Google Warns

June 25, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

‘What happens online stays online’ and other cyberbullying myths, debunked

September 11, 2025

How cybercriminals are targeting content creators

November 26, 2025

Drowning in spam or scam emails lately? Here’s why

January 27, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.