# CWE-436: Interpretation Conflict

**KEV-linked**

> As of 2026-10-05, CWE-436 (Interpretation Conflict) underlies 4 CVEs tracked by Threadlinqs, 1 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 9 tracked threats.

**Last updated:** 2026-10-05

## What is CWE-436?

Product A handles inputs or steps differently than Product B, which causes A to perform incorrect actions based on its perception of B's state.

This is generally found in proxies, firewalls, anti-virus software, and other intermediary devices that monitor, allow, deny, or modify traffic based on how the client or server is expected to behave.

CWE-436 is a class-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Not Language-Specific; Not Technology-Specific.

_Source: [MITRE CWE](https://cwe.mitre.org/data/definitions/436.html) (CWE-436 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data._

## Consequences

- **Integrity, Other** — Unexpected State, Varies by Context

_Source: MITRE CWE, common consequences._

## How CWE-436 is exploited in the wild

Threadlinqs maps 4 CVEs to CWE-436, published between 2026-07-17 and 2026-09-16. 1 is listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild. By CVSS v3 severity the set splits into 1 critical, 3 medium. The highest EPSS score in the set is 38.5% (CVE-2026-63030), the modelled probability of exploitation in the next 30 days. 9 tracked threats reference CWE-436 directly or through a CVE it covers; the most recent is “TIKTOUK Toolkit Harvests AWS, SMTP and Database Credentials from Exposed WordPress Backups and Config Files (CVE-2026-60137, CVE-2026-63030)” (2026-10-04). Affected products concentrate in nodemailer (2), WordPress (1), undici (1).

## Vulnerabilities (CVEs)

All 4 CVEs mapped to CWE-436, CISA KEV first, then by CVSS score.

- [CVE-2026-63030](https://intel.threadlinqs.com/cve/CVE-2026-63030) — CISA KEV · CVSS 9.8 critical · EPSS 38.5% · published 2026-07-17
- [CVE-2026-92597](https://intel.threadlinqs.com/cve/CVE-2026-92597) — CVSS 6.5 medium · published 2026-09-16
- [CVE-2026-92598](https://intel.threadlinqs.com/cve/CVE-2026-92598) — CVSS 6.5 medium · published 2026-09-16
- [CVE-2026-14643](https://intel.threadlinqs.com/cve/CVE-2026-14643) — CVSS 5.9 medium · EPSS 0.2% · published 2026-07-29

## Affected vendors

- **nodemailer** — 2 CVEs
- **WordPress** — 1 CVE
- **undici** — 1 CVE

## Threat activity

9 tracked threats cite CWE-436:

- [TIKTOUK Toolkit Harvests AWS, SMTP and Database Credentials from Exposed WordPress Backups and Config Files (CVE-2026-60137, CVE-2026-63030)](https://intel.threadlinqs.com/threat/TL-2026-2889) — HIGH · 2026-10-04
- [Chinese-Speaking 'Kapibala' Actor (Red Heron-Linked) Chains WordPress wp2shell, Zyxel GS1900, and Ubiquiti UniFi OS Flaws to Steal Government Data](https://intel.threadlinqs.com/threat/TL-2026-2619) — CRITICAL · 2026-09-22
- [AI-Agent-Driven Offensive Operation: Mass Cryptocurrency Wallet and Credential Compromise via Autonomous AI Coding Agents](https://intel.threadlinqs.com/threat/TL-2026-2070) — CRITICAL · 2026-08-19
- [AI-Assisted "HTTP Terminator" Uncovers Novel HTTP Desync Techniques and Apache Traffic Server Zero-Day (CVE-2026-63078)](https://intel.threadlinqs.com/threat/TL-2026-1961) — HIGH · 2026-08-09
- [WordPress Core XSS2Shell Vulnerability Chains Pre-Auth XSS to RCE (CVE-2026-64638)](https://intel.threadlinqs.com/threat/TL-2026-1933) — HIGH · 2026-08-07
- [wp2shell RCE Chain in WordPress Core (CVE-2026-60137, CVE-2026-63030) — Emergency Patch Released](https://intel.threadlinqs.com/threat/TL-2026-1465) — CRITICAL · 2026-07-18
- [wp2shell: WordPress Core REST API Batch-Route Confusion Chained with author__not_in SQL Injection (CVE-2026-63030 / CVE-2026-60137) Yields Unauthenticated Pre-Auth RCE](https://intel.threadlinqs.com/threat/TL-2026-1463) — CRITICAL · 2026-07-17
- [CVE-2026-63030 (wp2shell): Unauthenticated Remote Code Execution in WordPress Core REST API Batch Endpoint via Chained SQL Injection (CVE-2026-60137)](https://intel.threadlinqs.com/threat/TL-2026-1464) — CRITICAL · 2026-07-17
- [BadHost CVE-2026-48710 — Starlette HTTP Host Header Authentication Bypass Affecting FastAPI/AI Infrastructure (MCP, vLLM, LiteLLM)](https://intel.threadlinqs.com/threat/TL-2026-0606) — CRITICAL · 2026-05-27

## Related weaknesses

- [CWE-435](https://cwe.mitre.org/data/definitions/435.html)

Canonical: https://intel.threadlinqs.com/cwe/CWE-436
Source definition: https://cwe.mitre.org/data/definitions/436.html
Detection rules and IOCs for threats exploiting CWE-436 via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
