Cwe-134 - Use Of Externally-Controlled Format String - Cwe

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
April 27, 2026
Last Seen
July 18, 2026

Cwe-134 - Use Of Externally-Controlled Format String is a cwe tracked by ThreatCluster, appearing in 3 threat clusters built from 3 intelligence report mentions.

Cwe-134 - Use Of Externally-Controlled Format String is a cwe tracked across 3 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed April 27, 2026; most recent activity July 18, 2026.

Related Threat Clusters

  • Critical Vulnerability in Notepad++ Allows DoS and Memory Disclosure

    A format string injection vulnerability, tracked as CVE-2026-3008, has been identified in Notepad++ version 8.9.3. This flaw enables attackers to crash the application or leak sensitive memory information through a…

    6 articles · Updated April 27, 2026
  • Multiple High Severity Vulnerabilities Discovered in SurrealDB

    Three critical vulnerabilities (CVE-2024-58362, CVE-2024-58366, CVE-2024-58368) were published on July 18, 2026, affecting various versions of SurrealDB. CVE-2024-58362 allows unauthenticated attackers to execute…

    3 articles · Updated July 18, 2026
  • CVE-2026-7835: Format String Vulnerability in Netatalk

    CVE-2026-7835 is a format string vulnerability in Netatalk affecting versions prior to 4.4.3. It arises from a mismatch between format specifiers and argument types in logging functions, which could lead to stack memory…

    2 articles · Updated July 16, 2026

Recent Intelligence Reports

  • CVE-2024-58366 Vulnerability — CVSS 8.5, HIGH Severity — Ismalicious · July 18, 2026
  • CVE-2026-7835: Format string argument mismatch — Securin · July 15, 2026
  • Cve 2026 3008 — llgsjsm.github.io · April 27, 2026

Frequently asked questions

What is Cwe-134 - Use Of Externally-Controlled Format String?

Cwe-134 - Use Of Externally-Controlled Format String is a cwe tracked by ThreatCluster, appearing in 3 threat clusters built from 3 intelligence report mentions.

Is Cwe-134 - Use Of Externally-Controlled Format String still active?

The most recent intelligence report mentioning Cwe-134 - Use Of Externally-Controlled Format String on ThreatCluster is dated July 18, 2026. Activity was first observed April 27, 2026, giving a tracked span from then to July 18, 2026.

What is Cwe-134 - Use Of Externally-Controlled Format String associated with?

Across ThreatCluster reporting, Cwe-134 - Use Of Externally-Controlled Format String most frequently co-occurs with Data Breach, DDoS, Zero-day Exploit, Netatalk, CVE-2024-58366, among 8 tracked related entities.

What are the latest developments involving Cwe-134 - Use Of Externally-Controlled Format String?

The most significant recent cluster is “Critical Vulnerability in Notepad++ Allows DoS and Memory Disclosure” (6 articles · Updated April 27, 2026). Cwe-134 - Use Of Externally-Controlled Format String appears across 3 threat clusters in total, listed above with sources.

How much reporting does ThreatCluster have on Cwe-134 - Use Of Externally-Controlled Format String?

Cwe-134 - Use Of Externally-Controlled Format String appears in 3 intelligence report mentions across 3 deduplicated threat clusters, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown