{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/infinispan/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-15555"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["JBoss Marshalling","Infinispan"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"threat","_cs_vendors":["Red Hat"],"content_html":"\u003cp\u003eA critical vulnerability (CVE-2026-15555) has been identified in JBoss Marshalling, specifically affecting the Infinispan session replication mechanism. The flaw exists because the Infinispan session replication path utilizes the JBoss Marshalling River unmarshaller to process replicated session data without implementing any class filtering. This architectural oversight allows an attacker capable of injecting malicious serialized session data into the replication stream to trigger deserialization gadget chains. Successful exploitation results in remote code execution (RCE) on all nodes participating in the affected cluster. Given the nature of session replication, this vulnerability poses a significant risk to distributed Java applications, as exploitation of a single cluster node can propagate to all other nodes. Defenders should prioritize auditing applications that use JBoss Marshalling or Infinispan, focusing on network traffic monitoring between cluster nodes and the application of vendor-supplied patches.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for unauthenticated remote code execution on all cluster nodes, potentially leading to full system compromise, data exfiltration, and lateral movement within the environment. Affected sectors include any enterprise environment utilizing JBoss or Infinispan for session state management.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eApply the security updates provided by Red Hat to remediate CVE-2026-15555 across all infrastructure.\u003c/li\u003e\n\u003cli\u003eAudit network communication between Infinispan cluster nodes for anomalous serializable object traffic.\u003c/li\u003e\n\u003cli\u003eReview application configurations to ensure strict class filtering is enforced during deserialization, if currently configured to use JBoss Marshalling.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-11T09:48:03Z","date_published":"2026-08-11T09:48:03Z","id":"https://feed.craftedsignal.io/briefs/2026-08-jboss-marshalling-rce/","summary":"A deserialization vulnerability in JBoss Marshalling allows remote attackers to achieve code execution through the Infinispan session replication path.","title":"Remote Code Execution in JBoss Marshalling via Infinispan","url":"https://feed.craftedsignal.io/briefs/2026-08-jboss-marshalling-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Infinispan","version":"https://jsonfeed.org/version/1.1"}