XXE is a vulnerability tracked across 7 threat clusters and 9 intelligence report mentions on ThreatCluster. First observed November 28, 2025; most recent activity July 24, 2026.
Since July 2025, Russian state-backed hackers, known as Laundry Bear, have exploited a zero-click vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite to infiltrate Western government and commercial…
On June 11, 2026, Fedora released updates for XMLStarlet in versions 43 and 44 to address XML External Entity (XXE) vulnerabilities. These vulnerabilities could allow attackers to exploit XML parsing features,…
CISA has flagged critical vulnerabilities in DigiEver network video recorders and GeoServer, both of which are actively being exploited. The vulnerabilities have been added to the Known Exploited Vulnerabilities (KEV)…
A recently discovered vulnerability in GeoServer, identified as CVE-2025-58360, allows attackers to exploit insufficiently sanitized user input to define external entities within XML requests. This flaw has been…
Zimbra has released version 10.1.16 on February 4, 2026, to address high-severity vulnerabilities including cross-site scripting (XSS), XML external entity (XXE), and LDAP injection. Administrators are urged to upgrade…
A critical XML External Entity (XXE) vulnerability, tracked as CVE-2026-23795, has been disclosed in the Apache Syncope identity management console. This flaw can allow attackers to hijack active user sessions and…
Attackers have launched a dual campaign exploiting vulnerabilities in GlobalProtect portals and SonicWall APIs. A maximum-severity XML External Entity (XXE) vulnerability has been discovered in Apache, which could lead…