logo

CISA warns of actively exploited Apache HugeGraph-Server bug

ID: 1d3b67c0-4bbf-5621-a043-7945a0cedd12

STIX ID: report--1d3b67c0-4bbf-5621-a043-7945a0cedd12

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2024-09-19

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

**Executive Summary:** CISA added a critical RCE in Apache HugeGraph-Server (CVE-2024-27348, CVSS 9.8) to its Known Exploited Vulnerabilities catalog after observing active exploitation; Apache released version 1.3.0 to fix the issue and recommends using Java 11, enabling authentication, and applying IP/port whitelisting as mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.