What is CWE-436?
Product A handles inputs or steps differently than Product B, which causes A to perform incorrect actions based on its perception of B's state.
This is generally found in proxies, firewalls, anti-virus software, and other intermediary devices that monitor, allow, deny, or modify traffic based on how the client or server is expected to behave.
CWE-436 is a class-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Not Language-Specific; Not Technology-Specific.
Source: MITRE CWE (CWE-436 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.
Consequences
- Integrity, Other — Unexpected State, Varies by Context
Source: MITRE CWE, common consequences.
How CWE-436 is exploited in the wild
Threadlinqs maps 4 CVEs to CWE-436, published between 2026-07-17 and 2026-09-16. 1 is listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild. By CVSS v3 severity the set splits into 1 critical, 3 medium. The highest EPSS score in the set is 38.5% (CVE-2026-63030), the modelled probability of exploitation in the next 30 days. 9 tracked threats reference CWE-436 directly or through a CVE it covers; the most recent is “TIKTOUK Toolkit Harvests AWS, SMTP and Database Credentials from Exposed WordPress Backups and Config Files (CVE-2026-60137, CVE-2026-63030)” (2026-10-04). Affected products concentrate in nodemailer (2), WordPress (1), undici (1).
Vulnerabilities (CVEs)
All 4 CVEs mapped to CWE-436, CISA KEV first, then by CVSS score.
- CVE-2026-63030 — CISA KEV · CVSS 9.8 critical · EPSS 38.5% · published 2026-07-17
- CVE-2026-92597 — CVSS 6.5 medium · published 2026-09-16
- CVE-2026-92598 — CVSS 6.5 medium · published 2026-09-16
- CVE-2026-14643 — CVSS 5.9 medium · EPSS 0.2% · published 2026-07-29
Affected vendors
- nodemailer — 2 CVEs
- WordPress — 1 CVE
- undici — 1 CVE
Threat activity
9 tracked threats cite CWE-436:
- TIKTOUK Toolkit Harvests AWS, SMTP and Database Credentials from Exposed WordPress Backups and Config Files (CVE-2026-60137, CVE-2026-63030)HIGH
- Chinese-Speaking 'Kapibala' Actor (Red Heron-Linked) Chains WordPress wp2shell, Zyxel GS1900, and Ubiquiti UniFi OS Flaws to Steal Government DataCRITICAL
- AI-Agent-Driven Offensive Operation: Mass Cryptocurrency Wallet and Credential Compromise via Autonomous AI Coding AgentsCRITICAL
- AI-Assisted "HTTP Terminator" Uncovers Novel HTTP Desync Techniques and Apache Traffic Server Zero-Day (CVE-2026-63078)HIGH
- WordPress Core XSS2Shell Vulnerability Chains Pre-Auth XSS to RCE (CVE-2026-64638)HIGH
- wp2shell RCE Chain in WordPress Core (CVE-2026-60137, CVE-2026-63030) — Emergency Patch ReleasedCRITICAL
- wp2shell: WordPress Core REST API Batch-Route Confusion Chained with author__not_in SQL Injection (CVE-2026-63030 / CVE-2026-60137) Yields Unauthenticated Pre-Auth RCECRITICAL
- CVE-2026-63030 (wp2shell): Unauthenticated Remote Code Execution in WordPress Core REST API Batch Endpoint via Chained SQL Injection (CVE-2026-60137)CRITICAL
- BadHost CVE-2026-48710 — Starlette HTTP Host Header Authentication Bypass Affecting FastAPI/AI Infrastructure (MCP, vLLM, LiteLLM)CRITICAL