logo

Critical Apache Airflow Vulnerability Exposes Workflow Schedulers to Code Execution

ID: f3c048a1-77f4-5618-9941-b5789bacac29

STIX ID: report--f3c048a1-77f4-5618-9941-b5789bacac29

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-06-04

Date Updated: 2026-06-04

Author: Ddos

...
...

Security researchers disclosed CVE-2026-45360, a critical Apache Airflow scheduler deserialization flaw that allows the scheduler to instantiate attacker-controlled classes from untrusted serialized state, potentially executing code with an active database session and enabling severe manipulation or compromise; maintainers have released a fix and users should upgrade to Airflow 3.2.2+ and tighten DAG authoring permissions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.