A02:2025 Security Misconfiguration
Defaults are weak, hardening is incomplete, cloud / framework / server settings leave attack surface exposed.
Member CWEs (16)
- CWE-5 J2EE Misconfiguration: Data Transmission Without Encryption
- CWE-11 ASP.NET Misconfiguration: Creating Debug Binary
- CWE-13 ASP.NET Misconfiguration: Password in Configuration File
- CWE-15 External Control of System or Configuration Setting
- CWE-16
- CWE-260 Password in Configuration File
- CWE-315 Cleartext Storage of Sensitive Information in a Cookie
- CWE-489 Active Debug Code
- CWE-526 Cleartext Storage of Sensitive Information in an Environment Variable
- CWE-547 Use of Hard-coded, Security-relevant Constants
- CWE-611 Improper Restriction of XML External Entity Reference
- CWE-614 Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
- CWE-776 Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')
- CWE-942 Permissive Cross-domain Security Policy with Untrusted Domains
- CWE-1004 Sensitive Cookie Without 'HttpOnly' Flag
- CWE-1174 ASP.NET Misconfiguration: Improper Model Validation
Mapped NIST 800-53 r5 controls (3)
Our two-way, human-QA’d reading of how this category and each NIST 800-53 control relate. No external body publishes an OWASP→800-53 mapping, so these are our assessment.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Tagged CVEs (showing 50 most recent of 2,146)
- CVE-2026-76572
- CVE-2026-76227
- CVE-2026-75058
- CVE-2026-75055
- CVE-2026-74881
- CVE-2026-73661
- CVE-2026-73569
- CVE-2026-73235
- CVE-2026-72648
- CVE-2026-70604
- CVE-2026-70448
- CVE-2026-70423
- CVE-2026-69101
- CVE-2026-68517
- CVE-2026-67268
- CVE-2026-66405
- CVE-2026-66403
- CVE-2026-66065
- CVE-2026-66005
- CVE-2026-65893
- CVE-2026-65655
- CVE-2026-65432
- CVE-2026-65310
- CVE-2026-63407
- CVE-2026-62387
- CVE-2026-61736
- CVE-2026-59726
- CVE-2026-59148
- CVE-2026-59092
- CVE-2026-58378
- CVE-2026-58248
- CVE-2026-58191
- CVE-2026-57957
- CVE-2026-57948
- CVE-2026-57917
- CVE-2026-57259
- CVE-2026-57234
- CVE-2026-56817
- CVE-2026-56701
- CVE-2026-56586
- CVE-2026-56581
- CVE-2026-56567
- CVE-2026-56458
- CVE-2026-56076
- CVE-2026-55471
- CVE-2026-55110
- CVE-2026-54799
- CVE-2026-54798
- CVE-2026-54753
- CVE-2026-54470
Data: OWASP Top 10:2025 (CC BY-SA 4.0) · CWE memberships from cwe-api.mitre.org (meta-category CWE-1437).