Apache CXF Framework Patches Three Severe Security Flaws
ID: 1ecd3a5b-735e-5aa0-9a7c-491b47ff94b8
STIX ID: report--1ecd3a5b-735e-5aa0-9a7c-491b47ff94b8
Feed Name: securityonline.info
Threat Score
The advisory reports multiple critical vulnerabilities in Apache CXF—an LDAP injection in the XKMS certificate repository, an XML External Entity (XXE) flaw in WS-Transfer, and an incomplete fix enabling a remote code execution path via JMS (CVE-2026-44417)—affecting several branches; it recommends immediate upgrades to versions 4.2.1, 4.1.6, or 3.6.11 to mitigate these risks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
