{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aibmenterprise_build_of_quarkus/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ibm:enterprise_build_of_quarkus:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.6,"id":"CVE-2026-77874"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Enterprise Build of Quarkus (3.27.1-3.27.5.SP1, 3.33.1-3.33.3.SP1)"],"_cs_severities":["high"],"_cs_tags":["sql-injection","vulnerability","webserver"],"_cs_type":"advisory","_cs_vendors":["IBM"],"content_html":"\u003cp\u003eIBM Enterprise Build of Quarkus versions 3.27.1 through 3.27.5.SP1 and 3.33.1 through 3.33.3.SP1 are affected by a SQL injection vulnerability identified as CVE-2026-77874. This vulnerability permits a remote, unauthenticated attacker to inject malicious SQL statements into the application's processing layer. If successful, the attacker can interact directly with the underlying back-end database, potentially leading to unauthorized data exfiltration, information disclosure, data manipulation, or complete deletion of database records. Given the unauthenticated nature of the exploit, organizations utilizing these versions of the IBM Enterprise Build of Quarkus should prioritize security updates to mitigate the risk of data compromise.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthorized access to sensitive data stored in the application database. Depending on the database permissions and application configuration, this could result in significant data breaches, loss of integrity, or complete system compromise. The vulnerability affects a specific range of enterprise versions, making these organizations susceptible to targeted attacks focused on back-end data stores.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the IBM Enterprise Build of Quarkus to a version that addresses CVE-2026-77874.\u003c/li\u003e\n\u003cli\u003eReview database logs for suspicious SQL syntax or unusual query patterns following the identification of this vulnerability.\u003c/li\u003e\n\u003cli\u003eImplement Web Application Firewall (WAF) rules to detect and block common SQL injection payloads targeted at application endpoints.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-24T16:47:16Z","date_published":"2026-09-24T16:47:16Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-77874/","summary":"IBM Enterprise Build of Quarkus versions 3.27.1 through 3.27.5.SP1 and 3.33.1 through 3.33.3.SP1 are vulnerable to unauthenticated SQL injection, allowing attackers to access or modify back-end database content.","title":"SQL Injection Vulnerability in IBM Enterprise Build of Quarkus","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-77874/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:ibm:enterprise_build_of_quarkus:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}