logo

OpenAM CVE-2026-62379 (CVSS 9.8) Enables Unauthenticated Remote Code Execution, CVE-2026-62261 Scores CVSS 9.9

ID: f69b8971-b3cb-50b8-a259-1ff78c6f2d02

STIX ID: report--f69b8971-b3cb-50b8-a259-1ff78c6f2d02

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-07-31

Date Updated: 2026-08-01

Author: Do Son

...
...

OpenAM 16.1.2 patches four critical vulnerabilities — notably an unauthenticated RCE (CVE-2026-62379) and a Groovy sandbox escape (CVE-2026-62261) — that could allow full compromise of identity infrastructure; versions up to 16.1.1 are affected, no in-the-wild exploitation has been confirmed, and immediate upgrade plus recommended interim mitigations are advised.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.