logo

Apache CXF Framework Patches Three Severe Security Flaws

ID: 1ecd3a5b-735e-5aa0-9a7c-491b47ff94b8

STIX ID: report--1ecd3a5b-735e-5aa0-9a7c-491b47ff94b8

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-05-26

Date Updated: 2026-05-26

Author: Ddos

...
...

The advisory reports multiple critical vulnerabilities in Apache CXF—an LDAP injection in the XKMS certificate repository, an XML External Entity (XXE) flaw in WS-Transfer, and an incomplete fix enabling a remote code execution path via JMS (CVE-2026-44417)—affecting several branches; it recommends immediate upgrades to versions 4.2.1, 4.1.6, or 3.6.11 to mitigate these risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.