High-Severity RCE and XSS Vulnerabilities Patched in Apache Storm 2.8.6
ID: ce9ffb7c-f740-513d-99f3-d7beb21b47e1
STIX ID: report--ce9ffb7c-f740-513d-99f3-d7beb21b47e1
Feed Name: securityonline.info
Threat Score
Apache Storm 2.8.6 fixes two vulnerabilities: CVE-2026-35337, an unsafe deserialization flaw in the Nimbus Thrift API that can lead to remote code execution by authenticated topology submitters, and CVE-2026-35565, a stored cross-site scripting issue in the UI that can execute scripts in administrator sessions; immediate upgrade to 2.8.6 or applying the recommended mitigations (ObjectInputFilter allow-list and HTML-escaping of UI-supplied values) is advised.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
