Cwe-611 - Improper Restriction Of XML External Entity Reference (xxe) is a cwe tracked across 8 threat clusters and 11 intelligence report mentions on ThreatCluster. First observed April 29, 2026; most recent activity July 20, 2026.
Cisco has disclosed a critical authentication bypass vulnerability, CVE-2026-20182, affecting its Catalyst SD-WAN Controller and Manager. This flaw allows unauthenticated remote attackers to bypass authentication and…
On June 9, 2026, Microsoft released its largest Patch Tuesday update, addressing 206 vulnerabilities, including three zero-day flaws. Among the critical vulnerabilities, 32 were rated as critical, with 28 classified as…
On June 11, 2026, Fedora released updates for XMLStarlet in versions 43 and 44 to address XML External Entity (XXE) vulnerabilities. These vulnerabilities could allow attackers to exploit XML parsing features,…
On July 8, 2026, Foxit Software released updates for its PDF Reader and Editor to address 20 vulnerabilities, including multiple use-after-free flaws that could lead to remote code execution (RCE). The vulnerabilities,…
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding a vulnerability in GrassMarlin, a tool developed by the NSA, which could allow attackers to access sensitive information. This…
SUSE has released updates addressing a critical buffer overflow vulnerability (CVE-2026-25506) in the munge package, affecting multiple SUSE Linux versions. The vulnerability, which was published on February 10, 2026,…
A critical pre-authentication remote code execution vulnerability, CVE-2026-1731, has been identified in BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA). This vulnerability…
Microsoft has released Dusseldorf, an open-source out-of-band application security testing platform. This tool is designed to identify vulnerabilities that occur when applications interact with external systems, such as…