CVE-2026-64606: Apache Fury Critical Deserialization Flaw (CVSS 9.8)
ID: dc163acf-348c-5485-a8cf-db947cef7e10
STIX ID: report--dc163acf-348c-5485-a8cf-db947cef7e10
Feed Name: CosmicBytez Labs
**Executive Summary:** A critical deserialization-of-untrusted-data vulnerability (CVE-2026-64606, CVSS 9.8) in Apache Fury's Java lambda deserialization path allows attackers to bypass class-registration allowlists and potentially achieve arbitrary code execution; the issue affects Fury versions prior to 1.4.0 and is fixed in 1.4.0. Immediate remediation includes upgrading to Fury 1.4.0, enforcing class-registration, restricting deserialization sources, and applying defense-in-depth controls such as network segmentation and JVM auditing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
