Four security flaws described in the supplied Apache Struts advisories could expose affected applications to remote code execution, denial-of- service, and unintended data disclosure.
Recommended fixes include Struts 7.4.0 or later, or Struts 6.12.0 or later for organizations using the...
Apache Syncope has disclosed three important security vulnerabilities that could allow authorized administrators to execute malicious SQL commands, bypass Groovy sandbox protections, and impersonate higher-privileged users. The issues affect several Apache Syncope 3.0, 4.0, and 4.1 releases and have...
A public proof-of-concept exploit has been released for CVE-2026-23980, a SQL injection vulnerability affecting Apache Superset versions before 6.0.0.
The flaw could allow authenticated users with read-level access to trigger error-based SQL injection through specific application parameters.
Apache Superset is an...
A newly disclosed Apache Log4j2 issue could allow attackers to bypass a deserialization allowlist and execute code remotely in narrowly defined deployments.
The issue, tracked as Log4j2 #4255, affects applications that accept serialized Log4j events through a network-accessible Java deserialization...
Apache NiFi users should upgrade to version 2.11.0 after the project disclosed four security vulnerabilities affecting the NiFi Web API and Parameter Context authorization controls.
The flaws could enable authorization bypass, unauthorized configuration changes, validation abuse, memory exhaustion, and, in...
Apache has issued critical security updates for its Syncope identity and access management (IAM) platform to address multiple vulnerabilities, including remote code execution (RCE), SQL injection, privilege escalation, server-side request forgery (SSRF), and information disclosure.
These flaws affect various versions...
Apache ActiveMQ users are advised to urgently update their deployments after three important vulnerabilities were disclosed, exposing messaging infrastructure to denial-of-service (DoS) attacks, broken isolation, and improper authorization risks.
The issues, tracked as CVE-2026-53917, CVE-2026-54475, and CVE-2026-49877, affect core components...
A critical vulnerability in Apache ActiveMQ has been disclosed, allowing attackers to inject malicious HTTP security headers through improperly handled message properties, potentially leading to cross-site scripting and response manipulation attacks in affected deployments.
Tracked as CVE-2026-42253, the issue impacts...
The Apache MINA project has issued urgent security updates to address two critical vulnerabilities that could allow attackers to execute arbitrary code on affected systems.
Developers relying on this network application framework are strongly urged to update their software immediately...
More than 6,000 internet-exposed Apache ActiveMQ instances are still vulnerable to CVE-2026-34197. This newly tracked security flaw has now been added to the U.S. Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities (KEV) catalog.
The exposure data comes from The Shadowserver Foundation, which...