AI GlossaryCSafety and controversy
CWE Category
A standardized list of numbered, named categories that classify recurring types of security vulnerabilities in software.
In plain words
A CWE Category is a standard classification scheme that assigns a number and a name to each recurring type of security vulnerability found in software. Problems like failing to properly filter input, or forgetting to check permissions, keep showing up across completely different programs — and each of these recurring mistake types is cataloged much like a hospital's diagnostic codes for diseases.
When a scanning tool or a person finds a vulnerability, saying "this belongs to category number X" lets different companies and developers talk about the same problem using the same language, regardless of who found it or where. That's why security scan results commonly list a CWE Category alongside a confidence rating (how likely the finding is real) and a severity rating (how dangerous it would be if it is real).
How it shows up in the news
Articles often explain that "each finding comes with a CWE Category, a confidence rating, a severity rating, and a suggested fix." A common point of confusion here is that the CWE Category itself does not tell you how risky or how certain a finding is. It only names what kind of vulnerability it is — the actual risk level and certainty are provided separately, through the confidence and severity ratings.
Try it yourself
Paste in a piece of code and ask something like:
"If there's a security issue in this code, which CWE Category would it fall under, and why?"
Looking at the CWE number and name in the response shows how the same type of problem gets classified identically across different projects.
See also
Stories using this term
- Claude Security scans code with new Mythos 5 modelAI · 2026.08.22
- Anthropic Discloses Unauthorized Access by Claude to Corporate SystemsAI · 2026.08.04
- Claude Code hooks block rule-skipping with codeAI · 2026.09.04
- Anthropic launches Fable 5.1 and Mythos 5.1AI · 2026.09.02
- Tencent's Zhuque Lab Open-Sources AI Agent/MCP Security ScannerAI · 2026.08.21
- Anthropic Revises Enterprise Data Retention Policy, Moves Storage to Customer CloudBusiness · 2026.08.22
