CWE-776 - XML Entity Expansion - Cwe

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
August 26, 2026
Last Seen
August 26, 2026

Related Threat Clusters

  • Critical RCE Vulnerabilities Disclosed in NLTK Toolkit

    A mass disclosure of four CVEs affecting NLTK versions before 3.10.3 was announced, with CVE-2026-79657 rated at CVSS 9.8. This critical vulnerability allows remote code execution through unsafe pickle deserialization,…

    2 articles · Updated August 26, 2026

Recent Intelligence Reports

  • NLTK Mass Disclosure — 4 CVEs, Peak 9.8 (Allowlisted Pickle RCE) ThreatAft — Cybersecurity Intelligence / 12h A mass disclosure of four CVEs across versions before 3.10.3 just dropped, with CVE-2026-79657 leading at CVSS 9.8 — an unsafe pickle deserialization vulnerability where allowlisted pickle loaders trust entire module namespaces, allowing arbitrary code execution via crafted model files. CVSS 9.8 — Critical pickle deserialization RCE — CVE-2026-79657 allows attackers to execute arbitrary — threataft.com · August 26, 2026

CVSS v3.1 Breakdown