Skip to content
Product
Use it
Threat intelligence API
Free key, 70+ endpoints, OpenAPI. The product.
Get started
Pick your stack, make your first call.
Live feed
The console: incidents, filters, entities, search.
Recipes
Runnable examples for the free key.
Free feeds
RSS, ransomware feed, IOC blocklist, MISP — no key.
CLI & agents
tc from a terminal; agent keys with scoped budgets.
The data
Incident records
900 articles a day become ~70 scored incidents.
Dark web
First-party leak-site collection: victims, groups, markets.
Validated IOCs
Indicators with a false-positive gate; STIX, MISP, CSV.
Vulnerabilities
CVEs with EPSS, KEV and exploit status.
Entity graph
Actors, malware, CVEs, companies — pivotable.
For teams
For service providers
Per-client feeds, alerts and branded digests.
Use cases
How teams and builders use the corpus.
About ThreatCluster
What it is and how it is built.
Pricing
Docs
Reference
OpenAPI (Swagger)
Every endpoint, parameter and response model.
ReDoc
The same reference, long-form.
Examples on GitHub
curl, Python and Node quickstarts; daily spec snapshot.
Guides
Quickstart & plans
Key, scopes, budgets, tiers.
Integrations
Splunk, Sentinel, Elastic, agents and terminals, step by step
Export formats
STIX 2.1, MISP, CSV, text.
CLI setup
Install, log in, wire an agent.
Sign in
Get a free key
Product
Threat intelligence API
Get started
Live feed
Free feeds
CLI & agents
The data
Incident records
Dark web
Validated IOCs
Vulnerabilities
Entity graph
Docs
OpenAPI reference
Examples on GitHub
Integrations
Export formats
Pricing
For service providers
Use cases
Contact
Sign in
Get a free key
Back
Cwe-611 - Improper Restriction Of XML External Entity Reference (xxe) - Cwe
CWE Weakness
Threat entity extracted from intelligence sources
Sep 4: 0 mentions
Sep 5: 0 mentions
Sep 6: 0 mentions
Sep 7: 0 mentions
Sep 8: 2 mentions
Sep 9: 2 mentions
Sep 10: 2 mentions
Sep 4
Sep 7
Sep 10
Entities
›
cwe
›
Cwe-611 - Improper Restriction Of XML External Entity Reference (xxe)
Frequency
24
occurrences
First Seen
April 29, 2026
Last Seen
September 10, 2026
API
Overview
ThreatCluster AI
Recent Events
ThreatCluster AI
Profile
Profile
MITRE ATT&CK
1 / 2
Threat Actors
Sandworm
Malware
WormGPT
Tools
GrassMarlin
Microsoft Teams
Nginx
Saxon XSLT Processor
WinRM
CVEs
CVE-2026-6807
CVE-2026-20320
CVE-2026-47291
CVE-2026-47652
CVE-2026-76958
CVE-2026-76959
CVE-2026-76960
CVE-2026-76961
Sectors
Healthcare
Government
Energy
Public Health
-
REC
Recon
No techniques detected
-
RD
Resource Dev
No techniques detected
2
IA
Initial Access
T1190 - Exploit Public-Facing Application
T1566 - Phishing
1
EX
Execution
T1059.007 - JavaScript
-
PE
Persistence
No techniques detected
1
PE
Priv Esc
T1068 - Exploitation for Privilege Escalation
-
DE
Defense Evasion
No techniques detected
1
CA
Cred Access
T1003 - OS Credential Dumping
-
DI
Discovery
No techniques detected
-
LM
Lateral Mov
No techniques detected
-
CO
Collection
No techniques detected
-
C2
C2
No techniques detected
2
EX
Exfil
T1041 - Exfiltration Over C2 Channel
T1567 - Exfiltration Over Web Service
-
IM
Impact
No techniques detected
7
techniques detected across
5
tactics
Related Clusters (17)
Critical Zero-Day Vulnerability CVE-2026-20182 Exploited in Cisco SD-WAN Systems
May 14
·
131 sources
87
GeoNetwork Vulnerabilities Enable Unauthenticated RCE in Government Systems
Sep 2
·
6 sources
78
Sandworm Hackers Use Fake Job Interviews to Deploy Trojanized VPN Client
Aug 11
·
7 sources
77
Critical OVERPASS Vulnerability in SAP Kernel Requires Immediate Action
2d ago
·
16 sources
76
Microsoft September 2026 Patch Tuesday: Record 974 Vulnerabilities Addressed
2d ago
·
76 sources
73
Microsoft Issues Critical Security Patches for August 2026
Aug 12
·
2 sources
73
Critical CVE-2026-76658 Vulnerability in HPE Fabric Composer
Sep 2
·
2 sources
72
Microsoft June 2026 Patch Tuesday: Record 206 Vulnerabilities Addressed
Jun 9
·
57 sources
71
Cisco BroadWorks Vulnerability Exposes Sensitive Data to Remote Attackers
Aug 20
·
4 sources
68
Critical XML Entity Vulnerabilities Fixed in Fedora 43 and 44 Updates
Jun 11
·
2 sources
61
NextGen Mirth Connect Vulnerabilities Expose Healthcare Systems
4h ago
·
2 sources
61
Foxit Patches 20 Vulnerabilities in PDF Reader and Editor
Jul 9
·
5 sources
58
CISA Warns of Data-Theft Vulnerability in NSA's GrassMarlin Tool
Apr 29
·
3 sources
55
Claude Mythos Unleashes Vulnerability Discovery Bottleneck
1d ago
·
2 sources
37
SUSE Linux Munge Buffer Overflow Vulnerability Update
Feb 12
·
1584 sources
32
Critical RCE Vulnerability in BeyondTrust Remote Support and PRA
Feb 7
·
717 sources
30
Microsoft Launches Dusseldorf Open-Source OAST Platform for Vulnerability Detection
Jul 20
·
2 sources
28
Prev
1 / 4
Next
Related Articles (24)
Icsma 26 253 01
www.cisa.gov
·
4h ago
NextGen Mirth Connect Flaws Expose Downstream System Logins
Bankinfosecurity
·
5h ago
OWASP Top 10
www.techtarget.com
·
1d ago
Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero
Thehackernews
·
1d ago
September 2026
support.sap.com
·
2d ago
September 2026 security updates
support.sap.com
·
2d ago
CVE-2026-76658: Critical HPE Fabric Composer Flaw
Socprime
·
Sep 2
GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends
Thehackernews
·
Sep 2
Cisco External Entity Injection Vulnerability Allows Attackers to Read Sensitive Data
Ground.News
·
Aug 20
Cisco External Entity Injection Vulnerability Allows Attackers to Read Sensitive Data
Cybersecuritynews
·
Aug 20
Cisco BroadWorks Vulnerability Allows Remote Attackers to Access Sensitive Files
Gbhackers
·
Aug 20
Risky Bulletin: Russian hackers adopt the fake job interview tactics
News.Risky.Biz
·
Aug 12
August 2026 Monthly Patch
Csa.Sg
·
Aug 12
Microsoft open
Feeds.4Sysops
·
Jul 20
Security Bulletins
www.foxit.com
·
Jul 12
openSUSE Leap 16.0 python-biopython Moderate Info Leak CVE-2025
Linuxsecurity
·
Jun 30
Fedora 43 xmlstarlet Important XML Entity Issue Fix FEDORA-2026
Linuxsecurity
·
Jun 11
Fedora 44 XMLStarlet Critical XML Entity Issue Vuln 2026
Linuxsecurity
·
Jun 11
June Patch Tuesday marks a ‘new normal’ with over 200 CVEs, 32 rated ‘critical’
Csoonline
·
Jun 10
Microsoft Patch Tuesday for June 2026
Blog.Talosintelligence
·
Jun 9
CC-4784 - Exploitation of Zero-Day Vulnerability in Cisco Catalyst SD
Digital.Nhs.Uk
·
May 15
CISA flags data-theft bug in NSA-built OT networking tool
Theregister
·
Apr 29
CISA flags data-theft bug in NSA-built OT networking tool
Theregister
·
Apr 29
CISA flags data-theft bug in NSA
Theregister
·
Apr 29
Prev
1 / 5
Next
Related Entities
Sandworm
Data Breach
Sql Injection
Zero-day Exploit
Phishing
Denial of Service
Privilege Escalation
Server-Side Request Forgery (ssrf)
NextGen Healthcare
Azure
CVE-2026-6807
CVE-2026-20320