CISA warns about actively exploited Apache OFBiz RCE flaw
ID: d35e278d-a2da-5ef7-87b3-2985e2becc23
STIX ID: report--d35e278d-a2da-5ef7-87b3-2985e2becc23
Feed Name: Bleeping Computer
Threat Score
**CISA warns of active exploitation of Apache OFBiz vulnerabilities**: CVE-2024-32113 (path traversal enabling remote code execution) and a newer critical pre-auth RCE CVE-2024-38856 have public PoCs and are being actively exploited; agencies are directed to apply updates or mitigations (upgrade to OFBiz 18.12.15). The report also references an Android kernel zero-day (CVE-2024-36971) fixed by Google.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
