A09:2025 Security Logging and Alerting Failures
Security-relevant events aren't logged, alerts don't fire, or log integrity isn't protected — incidents go undetected.
Member CWEs (5)
- CWE-117 Improper Output Neutralization for Logs
- CWE-221 Information Loss or Omission
- CWE-223 Omission of Security-relevant Information
- CWE-532 Insertion of Sensitive Information into Log File
- CWE-778 Insufficient Logging
Mapped NIST 800-53 r5 controls (5)
Our two-way, human-QA’d reading of how this category and each NIST 800-53 control relate. No external body publishes an OWASP→800-53 mapping, so these are our assessment.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Tagged CVEs (showing 50 most recent of 1,330)
- CVE-2026-76375
- CVE-2026-76374
- CVE-2026-76208
- CVE-2026-75485
- CVE-2026-75057
- CVE-2026-74885
- CVE-2026-74870
- CVE-2026-71845
- CVE-2026-71474
- CVE-2026-68969
- CVE-2026-65945
- CVE-2026-65589
- CVE-2026-65311
- CVE-2026-64800
- CVE-2026-62948
- CVE-2026-62211
- CVE-2026-59947
- CVE-2026-59911
- CVE-2026-59326
- CVE-2026-56459
- CVE-2026-56457
- CVE-2026-54704
- CVE-2026-54652
- CVE-2026-54236
- CVE-2026-50316
- CVE-2026-50205
- CVE-2026-49426
- CVE-2026-49200
- CVE-2026-49088
- CVE-2026-48083
- CVE-2026-47234
- CVE-2026-46514
- CVE-2026-46467
- CVE-2026-46358
- CVE-2026-45679
- CVE-2026-45581
- CVE-2026-45565
- CVE-2026-45040
- CVE-2026-44969
- CVE-2026-44516
- CVE-2026-44479
- CVE-2026-44256
- CVE-2026-44105
- CVE-2026-44052
- CVE-2026-43992
- CVE-2026-43826
- CVE-2026-42282
- CVE-2026-41709
- CVE-2026-41495
- CVE-2026-41219
Data: OWASP Top 10:2025 (CC BY-SA 4.0) · CWE memberships from cwe-api.mitre.org (meta-category CWE-1444).