The product does not follow, or incorrectly follows, the chain of trust for a certificate back to a trusted root certificate.
Volume of CVEs assigned to CWE-296 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-24066HIGH Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.privileged.helper.tool, which exposes the XPC service com.slatedigital.connect.pr | Jun 10, 2026 | 8.4 | 32 | NO | NO |
CVE-2026-27134HIGH Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In versions 0.49.0 through 0.50.0, when using a custom Clust | Feb 21, 2026 | 8.1 | 30 | NO | NO |
CVE-2025-48057CRITICAL Icinga 2 is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. Prior to versions 2.12. | May 27, 2025 | 9.8 | 28 | NO | NO |
CVE-2026-44852HIGH An authenticated remote code execution vulnerability exists in the AOS-8 and AOS-10 web-based management interface. A vulnerability in the certificate download functionality could | May 12, 2026 | 7.2 | 27 | NO | NO |
CVE-2025-1146HIGH CrowdStrike uses industry-standard TLS (transport layer security) to secure communications from the Falcon sensor to the CrowdStrike cloud. CrowdStrike has identified a validation | Feb 12, 2025 | 8.1 | 26 | NO | NO |
CVE-2021-23162HIGH Improper validation of the cloud certificate chain in Mobile Connect allows man-in-the-middle attack to impersonate the legitimate Command Centre Server. This issue affects: Gallag | Nov 18, 2021 | 8.1 | 26 | NO | NO |
CVE-2019-3890HIGH It was discovered evolution-ews before 3.31.3 does not check the validity of SSL certificates. An attacker could abuse this flaw to get confidential information by tricking the use | Aug 1, 2019 | 8.1 | 26 | NO | NO |
CVE-2021-44532MEDIUM Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 converts SANs (Subject Alternative Names) to a string format. It uses this string to check peer certificates against hostnames | Feb 24, 2022 | 5.3 | 25 | NO | NO |
CVE-2021-1566HIGH A vulnerability in the Cisco Advanced Malware Protection (AMP) for Endpoints integration of Cisco AsyncOS for Cisco Email Security Appliance (ESA) and Cisco Web Security Appliance | Jun 16, 2021 | 7.4 | 24 | NO | NO |
CVE-2019-3762HIGH Data Protection Central versions 1.0, 1.0.1, 18.1, 18.2, and 19.1 contains an Improper Certificate Chain of Trust Vulnerability. A remote unauthenticated attacker could potentially | Mar 18, 2020 | 7.5 | 23 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.