XML External Entity - Vulnerability

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
November 24, 2025
Last Seen
November 25, 2025

XML External Entity is a vulnerability tracked by ThreatCluster, appearing in 2 threat clusters built from 2 intelligence report mentions.

XML External Entity is a vulnerability tracked across 2 threat clusters and 2 intelligence report mentions on ThreatCluster. First observed November 24, 2025; most recent activity November 25, 2025.

Related Threat Clusters

Recent Intelligence Reports

  • Ubuntu 25.10 OpenJDK 11 Critical Info Leak & XEE Attack USN-7882 — Linuxsecurity · November 25, 2025
  • USN-7885-1: OpenJDK 21 vulnerabilities — Ubuntu · November 24, 2025

Frequently asked questions

What is XML External Entity?

XML External Entity is a vulnerability tracked by ThreatCluster, appearing in 2 threat clusters built from 2 intelligence report mentions.

Is XML External Entity still active?

The most recent intelligence report mentioning XML External Entity on ThreatCluster is dated November 25, 2025. Activity was first observed November 24, 2025, giving a tracked span from then to November 25, 2025.

What is XML External Entity associated with?

Across ThreatCluster reporting, XML External Entity most frequently co-occurs with Data Breach, Ubuntu, CVE-2025-53057, CVE-2025-53066, CVE-2025-61748, among 8 tracked related entities.

What are the latest developments involving XML External Entity?

The most significant recent cluster is “Multiple OpenJDK Vulnerabilities Discovered in Ubuntu 25.10 and Derivatives” (11 articles · Updated December 2, 2025). XML External Entity appears across 2 threat clusters in total, listed above with sources.

How much reporting does ThreatCluster have on XML External Entity?

XML External Entity appears in 2 intelligence report mentions across 2 deduplicated threat clusters, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown