Record WatchRecord
Weakness shift: CWE-284 is now the #2 most common vulnerability type
25 July 2026 · Timeframe: Trailing 90 days vs the preceding 90
Over the last 90 days, CWE-284 (Improper Access Control) has moved into the #2 spot among all vulnerability types, displacing CWE-89 (Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')). The top of this ranking rarely moves, which is what makes a shift worth noting.
Why it matters
The weakness mix is one of the most stable signals in vulnerability data. When it shifts, it says something real about where new code is failing and where to aim secure-development and testing effort.
What to do
- CISOs. Check whether CWE-284 is covered by your testing and controls; a rising weakness type is a coverage question.
- Lean IT orgs. If you build software, add a improper access control check to code review; it is rising for a reason.
- MSPs. Fold CWE-284 into client secure-development guidance and testing baselines.
Our take
Tracking the weakness mix, not just the CVE count, is how you see where risk is actually moving. A shift in a stable ranking is a leading indicator.
The data behind this