Cyber Resilience

CWE · MITRE source

CWE-691Insufficient Control Flow Management

Abstraction: Pillar · CVEs in our corpus: 33

The code does not sufficiently manage its control flow during execution, creating conditions in which the control flow can be modified in unexpected ways.

Last updated: 20 August 2026 14:15 UTC

Cumulative inbound coverage

How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.

Collective: partial · 3 mapping(s) from 3 framework(s): CAPEC 1 (partial) · STIG windows 10 1 (partial) · STIG windows 11 1 (partial)

See the full cumulative-coverage rollup →

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • SA-24 Design For Cyber Resiliency
  • PR.PS-06
  • SC-2 Separation of System and User Functionality
  • SC-3 Security Function Isolation
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)
  • 2 hardening rules · 2 OS baselines
Validate
Prove the fix (OWASP ASVS)

NIST 800-53 r5 controls that address this weakness (1)AI-assisted

Control Title Family Why it addresses this CWE
SA-24Design For Cyber ResiliencySADesign principles and implementation approaches enforce robust control-flow management to maintain function and enable recovery after disruption.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2023-20559 6.68.80.00672023-04-02
CVE-2022-20697 6.48.60.01142022-04-15
CVE-2026-20271 6.18.60.00272026-08-05
CVE-2021-4106 5.77.80.00252022-02-16
CVE-2025-22893 5.37.80.00132025-08-12
CVE-2025-25273 5.37.80.00132025-08-12
CVE-2025-35963 5.27.40.00192025-11-11
CVE-2024-29079 5.16.80.00202024-11-13
CVE-2025-25774 5.16.50.00412025-03-12
CVE-2025-49463 5.16.50.00432025-07-10
CVE-2021-33157 5.07.20.00202024-02-23
CVE-2024-21801 5.07.10.00182024-08-14
CVE-2025-20004 4.97.20.00152025-05-13
CVE-2025-24305 4.97.20.00142025-08-12
CVE-2023-24587 4.86.90.00182023-11-14
CVE-2024-3847 4.86.10.00892024-04-17
CVE-2024-33617 4.75.90.00462024-11-13
CVE-2024-22374 4.66.50.00162024-08-14
CVE-2023-5102 4.55.30.00572023-10-09
CVE-2025-20022 4.35.70.00222025-05-13
CVE-2023-28711 4.25.50.00172023-08-11
CVE-2026-59384.15.50.00102026-04-27
CVE-2022-46828 3.95.20.00272022-12-08
CVE-2022-48481 3.95.20.00212023-04-28
CVE-2022-37409 3.64.70.00172023-05-10