logo

High-Severity RCE and XSS Vulnerabilities Patched in Apache Storm 2.8.6

ID: ce9ffb7c-f740-513d-99f3-d7beb21b47e1

STIX ID: report--ce9ffb7c-f740-513d-99f3-d7beb21b47e1

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-04-13

Date Updated: 2026-04-23

Author: Ddos

...
...

Apache Storm 2.8.6 fixes two vulnerabilities: CVE-2026-35337, an unsafe deserialization flaw in the Nimbus Thrift API that can lead to remote code execution by authenticated topology submitters, and CVE-2026-35565, a stored cross-site scripting issue in the UI that can execute scripts in administrator sessions; immediate upgrade to 2.8.6 or applying the recommended mitigations (ObjectInputFilter allow-list and HTML-escaping of UI-supplied values) is advised.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.