Threadlinqs IntelligenceStart free

Weakness · ClassCWE-436

CWE-436: Interpretation Conflict

KEV-linkedClass

As of 2026-10-05, CWE-436 (Interpretation Conflict) underlies 4 CVEs tracked by Threadlinqs, 1 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 9 tracked threats.

CVEs
4Mapped to CWE-436
CISA KEV
1Exploited in the wild
Critical
1CVSS v3 critical CVEs
Threats
9Tracked campaigns citing it
Likelihood
—MITRE likelihood of exploit

Last updated:

What is CWE-436?

Product A handles inputs or steps differently than Product B, which causes A to perform incorrect actions based on its perception of B's state.

This is generally found in proxies, firewalls, anti-virus software, and other intermediary devices that monitor, allow, deny, or modify traffic based on how the client or server is expected to behave.

CWE-436 is a class-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Not Language-Specific; Not Technology-Specific.

Source: MITRE CWE (CWE-436 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.

Consequences

  • Integrity, Other — Unexpected State, Varies by Context

Source: MITRE CWE, common consequences.

How CWE-436 is exploited in the wild

Threadlinqs maps 4 CVEs to CWE-436, published between 2026-07-17 and 2026-09-16. 1 is listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild. By CVSS v3 severity the set splits into 1 critical, 3 medium. The highest EPSS score in the set is 38.5% (CVE-2026-63030), the modelled probability of exploitation in the next 30 days. 9 tracked threats reference CWE-436 directly or through a CVE it covers; the most recent is “TIKTOUK Toolkit Harvests AWS, SMTP and Database Credentials from Exposed WordPress Backups and Config Files (CVE-2026-60137, CVE-2026-63030)” (2026-10-04). Affected products concentrate in nodemailer (2), WordPress (1), undici (1).

Vulnerabilities (CVEs)

All 4 CVEs mapped to CWE-436, CISA KEV first, then by CVSS score.

Affected vendors

  • nodemailer — 2 CVEs
  • WordPress — 1 CVE
  • undici — 1 CVE

Threat activity

9 tracked threats cite CWE-436: