Record WatchRecord
Weakness shift: CWE-416 is now the #3 most common vulnerability type
23 July 2026 · Timeframe: Trailing 90 days vs the preceding 90
Over the last 90 days, CWE-416 (Use After Free) has moved into the #3 spot among all vulnerability types, displacing CWE-862 (Missing Authorization). The top of this ranking rarely moves, which is what makes a shift worth noting.
Why it matters
The weakness mix is one of the most stable signals in vulnerability data. When it shifts, it says something real about where new code is failing and where to aim secure-development and testing effort.
What to do
- CISOs. Check whether CWE-416 is covered by your testing and controls; a rising weakness type is a coverage question.
- Lean IT orgs. If you build software, add a use after free check to code review; it is rising for a reason.
- MSPs. Fold CWE-416 into client secure-development guidance and testing baselines.
Our take
Tracking the weakness mix, not just the CVE count, is how you see where risk is actually moving. A shift in a stable ranking is a leading indicator.
The data behind this