Skip to content
Product
Use it
Threat intelligence API
Free key, 70+ endpoints, OpenAPI. The product.
Get started
Pick your stack, make your first call.
Live feed
The console: incidents, filters, entities, search.
Recipes
Runnable examples for the free key.
Free feeds
RSS, ransomware feed, IOC blocklist, MISP — no key.
CLI & agents
tc from a terminal; agent keys with scoped budgets.
The data
Incident records
900 articles a day become ~70 scored incidents.
Dark web
First-party leak-site collection: victims, groups, markets.
Validated IOCs
Indicators with a false-positive gate; STIX, MISP, CSV.
Vulnerabilities
CVEs with EPSS, KEV and exploit status.
Entity graph
Actors, malware, CVEs, companies — pivotable.
For teams
For service providers
Per-client feeds, alerts and branded digests.
Use cases
How teams and builders use the corpus.
About ThreatCluster
What it is and how it is built.
Pricing
Docs
Reference
OpenAPI (Swagger)
Every endpoint, parameter and response model.
ReDoc
The same reference, long-form.
Examples on GitHub
curl, Python and Node quickstarts; daily spec snapshot.
Guides
Quickstart & plans
Key, scopes, budgets, tiers.
Integrations
Splunk, Sentinel, Elastic, agents and terminals, step by step
Export formats
STIX 2.1, MISP, CSV, text.
CLI setup
Install, log in, wire an agent.
No results found
Sign in
Get a free key
No results found
Product
Threat intelligence API
Get started
Live feed
Recipes
Free feeds
CLI & agents
The data
Incident records
Dark web
Validated IOCs
Vulnerabilities
Entity graph
For teams
For service providers
Use cases
About ThreatCluster
Docs
OpenAPI (Swagger)
ReDoc
Examples on GitHub
Quickstart & plans
Integrations
Export formats
CLI setup
Pricing
Contact
Get a free key
Sign in
Back
CWE-611 - Improper Restriction Of XML External Entity Reference (xxe)
CWE Weakness
Threat entity extracted from intelligence sources
Sep 26: 0 mentions
Sep 27: 0 mentions
Sep 28: 0 mentions
Sep 29: 0 mentions
Sep 30: 0 mentions
Oct 1: 1 mention
Oct 2: 1 mention
Sep 26
Sep 29
Oct 2
Entities
›
cwe
›
CWE-611 - Improper Restriction Of XML External Entity Reference (xxe)
Frequency
44
occurrences
First Seen
April 29, 2026
Last Seen
October 2, 2026
API
Overview
Recent Events
Profile
Profile
MITRE ATT&CK
1 / 2
Tools
Nginx
GrassMarlin
CVEs
CVE-2026-76425
CVE-2026-76427
CVE-2026-76424
CVE-2026-6807
CVE-2026-76423
CVE-2026-76426
CVE-2026-76428
CVE-2026-20320
Regions
North Korea
Sectors
Healthcare
Government
-
REC
Recon
No techniques detected
-
RD
Resource Dev
No techniques detected
2
IA
Initial Access
T1190 - Exploit Public-Facing Application
T1566 - Phishing
1
EX
Execution
T1059 - Command and Scripting Interpreter
-
PE
Persistence
No techniques detected
-
PE
Priv Esc
No techniques detected
-
DE
Defense Evasion
No techniques detected
-
CA
Cred Access
No techniques detected
-
DI
Discovery
No techniques detected
-
LM
Lateral Mov
No techniques detected
-
CO
Collection
No techniques detected
-
C2
C2
No techniques detected
1
EX
Exfil
T1041 - Exfiltration Over C2 Channel
-
IM
Impact
No techniques detected
4
techniques detected across
3
tactics
Related Clusters (17)
Critical Zero-Day Vulnerability in Cisco ISE Under Active Exploitation
Sep 16
·
58 sources
89
GeoNetwork Vulnerabilities Enable Unauthenticated RCE in Government Systems
Sep 2
·
4 sources
78
Microsoft Issues Critical Security Patches for August 2026
Aug 12
·
2 sources
73
Critical CVE-2026-76658 Vulnerability in HPE Fabric Composer
Sep 2
·
2 sources
72
Critical Vulnerabilities in Atlassian Products Expose Systems to Remote Attacks
Sep 18
·
2 sources
72
Microsoft June 2026 Patch Tuesday: Record 206 Vulnerabilities Addressed
Jun 9
·
36 sources
71
Cisco BroadWorks Vulnerability Exposes Sensitive Data to Remote Attackers
Aug 20
·
3 sources
68
Critical XML Entity Vulnerabilities Fixed in Fedora 43 and 44 Updates
Jun 11
·
2 sources
61
NextGen Mirth Connect Vulnerabilities Expose Healthcare Systems
Sep 10
·
2 sources
61
Multiple Vulnerabilities Found in NivoCart Affecting Admin Access
Sep 20
·
2 sources
59
IBM webMethods Integration Server XXE Vulnerability Disclosed
Sep 11
·
27 sources
59
CVE-2026-88789: High-Risk XML Vulnerability in Apache Camel Quarkus
7h ago
·
2 sources
58
CISA Warns of Data-Theft Vulnerability in NSA's GrassMarlin Tool
Apr 29
·
3 sources
55
Siemba Launches Automated IDOR Testing for APIs
Sep 21
·
2 sources
46
SAML Protocol Criticized for Design Flaws Amidst Security Concerns
Sep 22
·
1 sources
40
Microsoft Launches Dusseldorf Open-Source OAST Platform for Vulnerability Detection
Jul 20
·
2 sources
28
RamziRange10 Exploit Enhances Vulnerability Testing Tools
Sep 14
·
2 sources
27
Prev
1 / 4
Next
Related Articles (44)
CVE-2026-88789 — CVSS 8.6, HIGH
Ismalicious
·
7h ago
Exploit for CVE-2026
Sploitus
·
1d ago
Security Bulletin node/7288641
www.ibm.com
·
6d ago
Security Bulletins
www.foxit.com
·
Sep 24
CVE Alert: CVE-2026-18184 – IBM – Financial Transaction Manager (FTM) for RedHat OpenShift
Redpacketsecurity
·
Sep 23
Synology SA 26 13
www.synology.com
·
Sep 23
SAML: A Fractal of Bad Design
News.Ycombinator
·
Sep 22
Siemba brings continuous IDOR testing to production APIs
Helpnetsecurity
·
Sep 21
Siemba Automates IDOR Detection Across Live APIs
Prnewswire
·
Sep 20
CVE-2026-94105: nivocart Vulnerability (CVSS 5.3) — Fix & Details
Strix.Ai
·
Sep 20
Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks
Thehackernews
·
Sep 17
Cisco Security Advisory: Cisco Identity Services Engine Vulnerabilities
Sec.Cloudapps.Cisco
·
Sep 17
Cisco Identity Services Engine Vulnerabilities
Sec.Cloudapps.Cisco
·
Sep 16
Security Bulletin - September 15 2026
Confluence.Atlassian
·
Sep 16
7284897
www.ibm.com
·
Sep 15
7284937
www.ibm.com
·
Sep 15
7284940
www.ibm.com
·
Sep 15
CVE Alert: CVE-2026-13275 – IBM
Redpacketsecurity
·
Sep 15
RamziRange10 exploit
Sploitus
·
Sep 14
CVE Alert: CVE-2026-2310 – IBM
Redpacketsecurity
·
Sep 11
Icsma 26 253 01
www.cisa.gov
·
Sep 10
NextGen Mirth Connect Flaws Expose Downstream System Logins
Bankinfosecurity
·
Sep 10
RamziRange3 exploit
Sploitus
·
Sep 10
OWASP Top 10
www.techtarget.com
·
Sep 9
Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero
Thehackernews
·
Sep 9
September 2026
support.sap.com
·
Sep 8
September 2026 security updates
support.sap.com
·
Sep 8
CVE-2026-76658: Critical HPE Fabric Composer Flaw
Socprime
·
Sep 2
GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends
Thehackernews
·
Sep 2
Cisco External Entity Injection Vulnerability Allows Attackers to Read Sensitive Data
Ground.News
·
Aug 20
Cisco External Entity Injection Vulnerability Allows Attackers to Read Sensitive Data
Cybersecuritynews
·
Aug 20
Cisco BroadWorks Vulnerability Allows Remote Attackers to Access Sensitive Files
Gbhackers
·
Aug 20
Risky Bulletin: Russian hackers adopt the fake job interview tactics
News.Risky.Biz
·
Aug 12
August 2026 Monthly Patch
Csa.Sg
·
Aug 12
Microsoft open
Feeds.4Sysops
·
Jul 20
openSUSE Leap 16.0 python-biopython Moderate Info Leak CVE-2025
Linuxsecurity
·
Jun 30
Fedora 43 xmlstarlet Important XML Entity Issue Fix FEDORA-2026
Linuxsecurity
·
Jun 11
Fedora 44 XMLStarlet Critical XML Entity Issue Vuln 2026
Linuxsecurity
·
Jun 11
June Patch Tuesday marks a ‘new normal’ with over 200 CVEs, 32 rated ‘critical’
Csoonline
·
Jun 10
Microsoft Patch Tuesday for June 2026
Blog.Talosintelligence
·
Jun 9
CC-4784 - Exploitation of Zero-Day Vulnerability in Cisco Catalyst SD
Digital.Nhs.Uk
·
May 15
CISA flags data-theft bug in NSA-built OT networking tool
Theregister
·
Apr 29
CISA flags data-theft bug in NSA-built OT networking tool
Theregister
·
Apr 29
CISA flags data-theft bug in NSA
Theregister
·
Apr 29
Prev
1 / 9
Next
Related Entities
Data Breach
Sql Injection
Zero-day Exploit
Phishing
Denial of Service
Cross-Site Scripting (xss)
Server-Side Request Forgery (ssrf)
DDoS
Privilege Escalation
XML External Entity (xxe)
Denial-of-Service
Server-Side Request Forgery