apache security advisories
60 threat alerts tracking vulnerabilities and security advisories that affect apache products.
Vulnios monitors apache CVE feeds, vendor advisories, CISA KEV listings, and exploit-prediction data continuously. Each alert below is enriched with severity, exploitation status, affected products, and a remediation path. Use this page to scan recent apache security news in one place, or click into an individual alert for full detail.
Critical Vulnerability: CVE-2026-82617 — apache — opennlp
The two built-in name-finder patterns exposed by opennlp.tools.namefind.RegexNameFinderFactory - DEFAULT_REGEX_NAME_FINDER.EMAIL and DEFAULT_REGEX_NAME_FINDER.URL - contain ambiguous nested quantifier
criticalCVE-2026-82617Critical Vulnerability: CVE-2026-49364 — apache — artemis
An unauthenticated network-adjacent attacker can leverage discovery to capture cluster administrative credentials during the initial cluster connection handshake. This issue affects Apache Artemis: f
criticalCVE-2026-49364Critical Vulnerability: CVE-2026-66906 — apache — camel
Relative path traversal vulnerability in Apache Camel Azure Storage Blob component. This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0.
criticalCVE-2026-66906Critical Vulnerability: CVE-2020-1938 — apache, fedoraproject — geode, tomcat
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HT
criticalCVE-2020-1938Critical Vulnerability: CVE-2026-69223 — apache — allura
Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the is
criticalCVE-2026-69223Critical Vulnerability: CVE-2026-73240 — apache — allura
Specifically crafted inputs may lead to git argument injection in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the
criticalCVE-2026-73240Critical Vulnerability: CVE-2026-66756 — apache — tika
Improper Protection of Alternate Path vulnerability in Apache Tika. This issue affects Apache Tika: from 4.0.0-alpha-1 before 4.0.0-beta-1. Users are recommended to upgrade to version 4.0.0-beta-1,
criticalCVE-2026-66756Critical Vulnerability: CVE-2026-32327 — apache — apr-util
A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users ar
criticalCVE-2026-32327Critical Vulnerability: CVE-2026-34191 — apache — apr-util
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider. This issue affects Apache Portable R
criticalCVE-2026-34191Critical Vulnerability: CVE-2026-60053 — apache — answer
Insufficient Session Expiration vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Administrative API keys remained usable after the owning administrator was demoted or
criticalCVE-2026-60053Critical Vulnerability: CVE-2026-68979 — apache — nifi
Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization checking on components referencing Parameter values. Updating a Parameter Conte
criticalCVE-2026-68979Critical Vulnerability: CVE-2026-68980 — apache — nifi
Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API. The framework authorizes asset deletion against the owning Para
criticalCVE-2026-68980Critical Vulnerability: CVE-2026-34486 — apache, redhat — tomcat, jboss_web_server
Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53
criticalCVE-2026-34486Critical Vulnerability: CVE-2026-48144 — apache — thrift
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.2
criticalCVE-2026-48144Critical Vulnerability: CVE-2026-55971 — apache — thrift
Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
criticalCVE-2026-55971Critical Vulnerability: CVE-2026-58023 — apache — thrift
Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
criticalCVE-2026-58023Critical Vulnerability: CVE-2026-58662 — apache — thrift
Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade
criticalCVE-2026-58662Critical Vulnerability: CVE-2026-53405 — apache — syncope
Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can import arbitrary BPMN process definitions via the REST API and then start t
criticalCVE-2026-53405Critical Vulnerability: CVE-2026-53421 — apache — syncope
Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve remote code execution through the connector subsystem by relying
criticalCVE-2026-53421Critical Vulnerability: CVE-2026-57308 — apache — syncope
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary SQ
criticalCVE-2026-57308Critical Vulnerability: CVE-2026-62183 — apache — syncope
Improper Privilege Management vulnerability in Apache Syncope. When: * the all-Java user workflow adapter is configured, or * the Flowable user workflow adapter is configured, bearing a BPMN definit
criticalCVE-2026-62183Critical Vulnerability: CVE-2026-63071 — apache — syncope
Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious Groovy class containing untrusted co
criticalCVE-2026-63071Critical Vulnerability: CVE-2026-62390 — apache — kylin
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin. A backend API refreshing table catalog may cause the injection to the generated SQL.
criticalCVE-2026-62390Critical Vulnerability: CVE-2026-62392 — apache — kylin
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. A backend API may bring job config parameters to OS command line. This issue
criticalCVE-2026-62392Critical Vulnerability: CVE-2024-36265 — apache — submarine
** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Submarine Server Core. This issue affects Apache Submarine Server Core: from 0.8.0. An attacker can bypass authenticat
criticalCVE-2024-36265Critical Vulnerability: CVE-2026-47898 — apache — lucene.net
Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.Common library). This issue affects Apache Lucene.Net.Analysis.Common: from 4.8.0-beta000
criticalCVE-2026-47898Critical Vulnerability: CVE-2026-40047 — apache — camel
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache Camel Docling component. The camel-docling component invokes the external `docling` command-
criticalCVE-2026-40047Critical Vulnerability: CVE-2026-46454 — apache — camel
Improper Input Validation vulnerability in Apache Camel Cometd Component. The camel-cometd component maps inbound Bayeux (CometD) message headers into the Camel Exchange without applying a HeaderFilt
criticalCVE-2026-46454Critical Vulnerability: CVE-2026-44930 — apache — cxf
An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository. Users are recommended
criticalCVE-2026-44930Critical Vulnerability: CVE-2026-39999 — apache — apisix
Authentication Bypass by Spoofing vulnerability in Apache APISIX. The attacker can completely bypass authentication capitalising on certain configurations of jwt-auth plugin. This issue affects Apach
criticalCVE-2026-39999Critical Vulnerability: CVE-2026-44087 — apache — apisix
Insufficient Verification of Data Authenticity vulnerability in Apache APISIX. The openid-connect plugin under default configuration has an attack surface that allows the attacker to spoof identity h
criticalCVE-2026-44087Critical Vulnerability: CVE-2026-49230 — apache — apisix
Improper Validation of Integrity Check Value vulnerability in Apache APISIX. The jwe-decrypt plugin under default configuration is vulnerable to authentication bypass. This issue affects Apache APIS
criticalCVE-2026-49230Critical Vulnerability: CVE-2026-49871 — apache — apisix
Cross-Site Request Forgery (CSRF) vulnerability in the cas-auth plugin under default configurations. This defect allows a remote attacker that manages to send a victim to a webpage controlled by them
criticalCVE-2026-49871Critical Vulnerability: CVE-2026-49268 — apache — shiro
A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in DefaultLdapRealm class. User-supplied username input is directly concatenated into the LDAP DN tem
criticalCVE-2026-49268Critical Vulnerability: CVE-2026-50203 — apache — apache-airflow-providers-sftp
A path traversal in the SFTP provider (`SFTPHook.retrieve_directory` / `SFTPOperator(operation=get)`) let a malicious or compromised remote SFTP server write files outside the configured local destina
criticalCVE-2026-50203Critical Vulnerability: CVE-2026-32967 — apache — dolphinscheduler
Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to versio
criticalCVE-2026-32967Critical Vulnerability: CVE-2026-32966 — apache — dolphinscheduler
DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommen
criticalCVE-2026-32966Critical Vulnerability: CVE-2026-50627 — apache — cxf
The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issued for one Resource Server to be successfully replaye
criticalCVE-2026-50627Critical Vulnerability: CVE-2026-50628 — apache — cxf
A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address. Enabling this security feature inadve
criticalCVE-2026-50628Critical Vulnerability: CVE-2026-49875 — apache — cxf
Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity reso
criticalCVE-2026-49875Critical Vulnerability: CVE-2026-45434 — apache — ofbiz
Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgra
criticalCVE-2026-45434Critical Vulnerability: CVE-2026-25199 — apache — cloudstack
Instances deployed via the Proxmox extension allow unauthorized access to instances belonging to other tenants. This issue affects Apache CloudStack: from 4.21.0.0 through 4.22.0.0. The Proxmo
criticalCVE-2026-25199Critical Vulnerability: CVE-2026-40010 — apache — wicket
Missing invocation of Servlet http web request method changeSessionId after session binding can be exploited for a session fixation attack in Apache Wicket. This issue affects Apache Wicket: from 8.0
criticalCVE-2026-40010Critical Vulnerability: CVE-2016-1000031 — apache — commons_fileupload
Apache Commons FileUpload before 1.3.3 DiskFileItem File Manipulation Remote Code Execution
criticalCVE-2016-1000031Critical Vulnerability: CVE-2015-1832 — apache — derby
XML external entity (XXE) vulnerability in the SqlXmlUtil code in Apache Derby before 10.12.1.1, when a Java Security Manager is not in place, allows context-dependent attackers to read arbitrary file
criticalCVE-2015-1832Critical Vulnerability: CVE-2016-5019 — apache — myfaces_trinidad
CoreResponseStateManager in Apache MyFaces Trinidad 1.0.0 through 1.0.13, 1.2.x before 1.2.15, 2.0.x before 2.0.2, and 2.1.x before 2.1.2 might allow attackers to conduct deserialization attacks via a
criticalCVE-2016-5019Critical Vulnerability: CVE-2016-4436 — apache — struts
Apache Struts 2 before 2.3.29 and 2.5.x before 2.5.1 allow attackers to have unspecified impact via vectors related to improper action name clean up.
criticalCVE-2016-4436Critical Vulnerability: CVE-2016-4464 — apache — cxf_fediz
The application plugins in Apache CXF Fediz 1.2.x before 1.2.3 and 1.3.x before 1.3.1 do not match SAML AudienceRestriction values against configured audience URIs, which might allow remote attackers
criticalCVE-2016-4464Critical Vulnerability: CVE-2016-4438 — apache — struts
The REST plugin in Apache Struts 2 2.3.19 through 2.3.28.1 allows remote attackers to execute arbitrary code via a crafted expression.
criticalCVE-2016-4438Critical Vulnerability: CVE-2016-4432 — apache — qpid_broker-j
The AMQP 0-8, 0-9, 0-91, and 0-10 connection handling in Apache Qpid Java before 6.0.3 might allow remote attackers to bypass authentication and consequently perform actions via vectors related to con
criticalCVE-2016-4432Critical Vulnerability: CVE-2016-3087 — apache — struts
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via vectors related to an ! (exc
criticalCVE-2016-3087Critical Vulnerability: CVE-2016-3082 — apache — struts
XSLTResult in Apache Struts 2.x before 2.3.20.2, 2.3.24.x before 2.3.24.2, and 2.3.28.x before 2.3.28.1 allows remote attackers to execute arbitrary code via the stylesheet location parameter.
criticalCVE-2016-3082Critical Vulnerability: CVE-2016-0733 — apache — ranger
The Admin UI in Apache Ranger before 0.5.1 does not properly handle authentication requests that lack a password, which allows remote attackers to bypass authentication by leveraging knowledge of a va
criticalCVE-2016-0733Critical Vulnerability: CVE-2016-2170 — apache — ofbiz
Apache OFBiz 12.04.x before 12.04.06 and 13.07.x before 13.07.03 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections li
criticalCVE-2016-2170Critical Vulnerability: CVE-2015-3252 — apache — cloudstack
Apache CloudStack before 4.5.2 does not properly preserve VNC passwords when migrating KVM virtual machines, which allows remote attackers to gain access by connecting to the VNC server.
criticalCVE-2015-3252Critical Vulnerability: CVE-2015-5344 — apache — camel
The camel-xstream component in Apache Camel before 2.15.5 and 2.16.x before 2.16.1 allow remote attackers to execute arbitrary commands via a crafted serialized Java object in an HTTP request.
criticalCVE-2015-5344Critical Vulnerability: CVE-2026-42027 — apache — opennlp
Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader Versions Affected: before 2.5.9, before 3.0.0-M3 Description: The ExtensionLoader.instantiateExtension(Cl
criticalCVE-2026-42027Critical Vulnerability: CVE-2026-40682 — apache — opennlp
XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersistor Versions Affected: before 2.5.9, before 3.0.0-M3 Description: The DictionaryEntryPersistor c
criticalCVE-2026-40682Critical Vulnerability: CVE-2026-42779 — apache — mina
The fix for CVE-2026-41635 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description: Apache MINA's AbstractIoBuffer.resolveClass() contains two branches, one
criticalCVE-2026-42779Critical Vulnerability: CVE-2026-42778 — apache — mina
The fix for CVE-2026-41409 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description: The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was inco
criticalCVE-2026-42778
Showing the 60 most recent. Older alerts are archived but still reachable via search and the main feed.
Track apache exposure across your environment
Vulnios automatically cross-references your asset inventory against new apache CVEs and surfaces only what affects you. No more sifting manually — actionable findings only.
Start a free scan