Exploited: CISA Highlights Apache OFBiz Flaw After PoC Emerges
ID: e2ef52aa-e715-5c3d-be1a-452180c1bebd
STIX ID: report--e2ef52aa-e715-5c3d-be1a-452180c1bebd
Feed Name: Dark Reading
Date Published: 2024-08-29
Date Updated: 2026-04-21
Author: Kristina Beek, Associate Editor, Dark Reading
Apache OFBiz has a critical pre-authentication RCE (CVE-2024-38856, CVSS 9.8) that affects all versions up to 18.12.14; SonicWall researchers discovered the flaw while testing fixes for a related vulnerability and published an exploit chain and PoC details. CISA added the issue to its Known Exploited Vulnerabilities catalog, public PoCs and observed exploitation attempts increase real-world risk, and organizations (including federal agencies) are urged to upgrade to 18.12.15 immediately to mitigate the threat.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
