Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2955 articles · 162982 vulns · 38/41 feeds (7d)
← Back to list
EST
PRE-CVE

OWASP Top 10 2025 Changes and Recommendations

56% confidence

Description

The 2025 OWASP Top 10 introduces two new categories: Software Supply Chain Failures (A03) and Mishandling of Exceptional Conditions (A10). Security Misconfiguration rises to #2, while Broken Access Control (A01) now explicitly includes BOLA and BFLA API authorization failures. The update reflects shifts in attack patterns and emphasizes gaps in tooling and SDLC maturity.

Related News (1 articles)

Tier C
Qualys Blog3h ago
What Changed in OWASP Top 10 2025 and Recommendations for Each Category
→ No new info (linked only)
CISA KEV❌ No
Actively exploited❌ No
PublishedJun 15, 2026
Last enriched3h ago
Tags
owaspsecurity misconfigurationapi securitysupply chainaccess control
Trending Score20
Source articles1
Independent1
Info Completeness2/14
Missing: cve_id, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Pin to Dashboard

Verification

State: reported
Confidence: 56%

Vulnerability Timeline

CVE Published
Jun 15, 2026
Discovered by ZDM
Jun 15, 2026