CWE-693— Protection Mechanism Failure
The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.— MITRE CWE catalog
661 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-693page 10 of 14
- CVE-2026-12296CRITICALCVSS 9.6EG 9.62026-06-16
Sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
- CVE-2026-12302MEDIUMCVSS 6.5EG 6.52026-06-16
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.
- CVE-2026-12315CRITICALCVSS 9.1EG 9.12026-06-16
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
- CVE-2026-12316CRITICALCVSS 9.1EG 9.12026-06-16
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.
- CVE-2026-1232MEDIUMCVSS 6.8EG 6.82026-02-02
A medium-severity vulnerability has been identified in BeyondTrust Privilege Management for Windows versions <=25.7. Under certain conditions, a local authenticated user with elevated privileges may be able to bypass the product’s anti-t…
- CVE-2026-12438HIGHCVSS 8.3EG 8.32026-06-17
Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium secur…
- CVE-2026-12457MEDIUMCVSS 4.2EG 4.22026-06-17
Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-13601HIGHCVSS 6.5EG 7.12026-06-29
A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS…
- CVE-2026-13859CRITICALCVSS 9.6EG 9.62026-06-30
Inappropriate implementation in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-13862MEDIUMCVSS 6.5EG 6.52026-06-30
Insufficient policy enforcement in Web Authentication (Passkeys & Security Keys) in Google Chrome on iOS prior to 150.0.7871.47 allowed an attacker in a privileged network position to leak cross-origin data via a crafted HTML page. (Chromi…
- CVE-2026-13876MEDIUMCVSS 6.5EG 6.52026-06-30
Inappropriate implementation in Network in Google Chrome prior to 150.0.7871.47 allowed an attacker in a privileged network position to bypass content security policy via malicious network traffic. (Chromium security severity: Medium)
- CVE-2026-13886MEDIUMCVSS 6.5EG 6.52026-06-30
Insufficient policy enforcement in Isolated Web Apps in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-13904MEDIUMCVSS 6.5EG 6.52026-06-30
Inappropriate implementation in Safe Browsing in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-13909CRITICALCVSS 9.6EG 9.62026-06-30
Insufficient policy enforcement in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security seve…
- CVE-2026-13910MEDIUMCVSS 6.5EG 6.52026-06-30
Insufficient policy enforcement in WebXR in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-13951HIGHCVSS 8.3EG 8.32026-06-30
Insufficient policy enforcement in USB in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity:…
- CVE-2026-14017CRITICALCVSS 9.6EG 9.62026-06-30
Inappropriate implementation in Navigation in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security sever…
- CVE-2026-14037CRITICALCVSS 9.6EG 9.62026-06-30
Insufficient policy enforcement in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity:…
- CVE-2026-14050MEDIUMCVSS 6.5EG 6.52026-06-30
Insufficient policy enforcement in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-14058MEDIUMCVSS 4.3EG 4.32026-06-30
Insufficient policy enforcement in Parser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-14059MEDIUMCVSS 6.5EG 6.52026-06-30
Insufficient policy enforcement in Related-Website-Sets in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-14076MEDIUMCVSS 4.3EG 4.32026-06-30
Insufficient policy enforcement in Network in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-14092MEDIUMCVSS 4.3EG 4.32026-06-30
Insufficient policy enforcement in Privacy in Google Chrome prior to 150.0.7871.47 allowed an attacker in a privileged network position to leak cross-origin data via malicious network traffic. (Chromium security severity: Low)
- CVE-2026-14095CRITICALCVSS 9.6EG 9.62026-06-30
Insufficient policy enforcement in Browser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security sever…
- CVE-2026-14097CRITICALCVSS 9.6EG 9.62026-06-30
Inappropriate implementation in WebAppInstalls in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium sec…
- CVE-2026-14101CRITICALCVSS 9.6EG 9.62026-06-30
Insufficient policy enforcement in Sandbox in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium securit…
- CVE-2026-14120CRITICALCVSS 9.6EG 9.62026-07-01
Inappropriate implementation in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severit…
- CVE-2026-14151CRITICALCVSS 8.3EG 9.62026-07-01
Inappropriate implementation in AI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-14409HIGHCVSS 7.5EG 7.52026-07-02
Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium secur…
- CVE-2026-14440MEDIUMCVSS 6.8EG 6.82026-07-02
Description: To issue and renew TLS certificates on behalf of customers, Cloudflare's Universal SSL feature automatically manages the CAA RRset for the customer's zone. This auto-managed RRset is permissive by design (e.g. 'issue "lets…
- CVE-2026-14535CRITICALCVSS 9.8EG 9.82026-07-04
In Trail of Bits fickling versions up to and including 0.1.11, the UnsafeImportsML analysis pass unconditionally calls AnalysisContext.shorten_code(node) on every import node it inspects, regardless of whether the import is flagged as unsa…
- CVE-2026-14625MEDIUMCVSS 6.3EG 6.32026-07-04
A security flaw has been discovered in NousResearch hermes-agent up to 0.15.2. The affected element is the function shell.exec of the file tui_gateway/server.py. The manipulation results in protection mechanism failure. It is possible to l…
- CVE-2026-15528LOWCVSS 3.3EG 3.32026-07-13
A vulnerability was found in lamaalrajih kicad-mcp up to 3.3.1. This issue affects some unknown processing of the file kicad_mcp/utils/path_validator.py. Performing a manipulation of the argument project_path/schematic_path results in prot…
- CVE-2026-15618MEDIUMCVSS 6.3EG 6.32026-07-13
A security flaw has been discovered in mosaxiv clawlet up to 0.2.10. The affected element is the function guardExecCommand of the file tools/tool_exec.go of the component exec Safety Guard. The manipulation results in protection mechanism …
- CVE-2026-16356CRITICALCVSS 9.8EG 9.82026-07-21
Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
- CVE-2026-16370CRITICALCVSS 9.1EG 9.12026-07-21
Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
- CVE-2026-16377CRITICALCVSS 9.8EG 9.82026-07-21
Mitigation bypass in the PDF Viewer component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
- CVE-2026-16380CRITICALCVSS 9.1EG 9.12026-07-21
Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
- CVE-2026-16382CRITICALCVSS 9.8EG 9.82026-07-21
Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
- CVE-2026-16383CRITICALCVSS 9.8EG 9.82026-07-21
Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
- CVE-2026-16388CRITICALCVSS 9.8EG 9.82026-07-21
Sandbox escape in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
- CVE-2026-16390CRITICALCVSS 9.1EG 9.12026-07-21
Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
- CVE-2026-16394CRITICALCVSS 9.1EG 9.12026-07-21
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
- CVE-2026-16406CRITICALCVSS 9.1EG 9.12026-07-21
Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
- CVE-2026-16407CRITICALCVSS 9.8EG 9.82026-07-21
Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
- CVE-2026-20665MEDIUMCVSS 6.5EG 6.52026-03-25
This issue was addressed through improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. Processing maliciously crafte…
- CVE-2026-20667HIGHCVSS 8.8EG 8.82026-02-11
A logic issue was addressed with improved checks. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, watchOS 26.3. An app may be able to break out of its sandbox.
- CVE-2026-20701HIGHCVSS 7.5EG 7.52026-03-25
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to connect to a network share without user consent.
- CVE-2026-20824MEDIUMCVSS 5.5EG 5.52026-01-13
Protection mechanism failure in Windows Remote Assistance allows an unauthorized attacker to bypass a security feature locally.
- CVE-2026-21510CRITICALCVSS 8.8EG 9.0⚠ KEV2026-02-10
Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.
Map vulnerabilities like CWE-693 to your infrastructure
EchelonGraph correlates every CVE — across CWE-693 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →