logo

CVE-2026-64606: Apache Fury Critical Deserialization Flaw (CVSS 9.8)

ID: dc163acf-348c-5485-a8cf-db947cef7e10

STIX ID: report--dc163acf-348c-5485-a8cf-db947cef7e10

Feed Name: CosmicBytez Labs

Threat Score
80/100

Date Published: 2026-07-22

Date Updated: 2026-07-22

...
...

**Executive Summary:** A critical deserialization-of-untrusted-data vulnerability (CVE-2026-64606, CVSS 9.8) in Apache Fury's Java lambda deserialization path allows attackers to bypass class-registration allowlists and potentially achieve arbitrary code execution; the issue affects Fury versions prior to 1.4.0 and is fixed in 1.4.0. Immediate remediation includes upgrading to Fury 1.4.0, enforcing class-registration, restricting deserialization sources, and applying defense-in-depth controls such as network segmentation and JVM auditing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.