logo

CISA warns about actively exploited Apache OFBiz RCE flaw

ID: d35e278d-a2da-5ef7-87b3-2985e2becc23

STIX ID: report--d35e278d-a2da-5ef7-87b3-2985e2becc23

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2024-08-08

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

**CISA warns of active exploitation of Apache OFBiz vulnerabilities**: CVE-2024-32113 (path traversal enabling remote code execution) and a newer critical pre-auth RCE CVE-2024-38856 have public PoCs and are being actively exploited; agencies are directed to apply updates or mitigations (upgrade to OFBiz 18.12.15). The report also references an Android kernel zero-day (CVE-2024-36971) fixed by Google.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.