Critical Apache Tika Core Vulnerability Exploited by Uploading Malicious PDF
ID: 80c21f3d-1356-5d92-b300-87dc701cbfb0
STIX ID: report--80c21f3d-1356-5d92-b300-87dc701cbfb0
Feed Name: cybersecurityNews.com
Threat Score
A critical XXE vulnerability (CVE-2025-66516) in Apache Tika enables attackers to exploit crafted XFA PDF files to execute arbitrary code, exfiltrate data, or gain unauthorized access; the flaw affects multiple Tika components and versions across all operating systems, is rated CVSS 9.8, and Apache recommends upgrading Tika-core to 3.2.2+ and restricting untrusted PDF uploads until patched.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
