{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/enterprise-application/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-15560"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["JBoss Enterprise Application Platform"],"_cs_severities":["high"],"_cs_tags":["remote-code-execution","vulnerability","jboss","denial-of-service","web-server","enterprise-application","java","jndi"],"_cs_type":"advisory","_cs_vendors":["Red Hat"],"content_html":"\u003cp\u003eCVE-2026-15560 is a critical security flaw affecting Red Hat JBoss Enterprise Application Platform (EAP) when the security manager is enabled via the '-secmgr' flag. The vulnerability resides within the openjdk-orb's JDKBridge component. During the process of object unmarshalling on port 3528, the JDKBridge component fails to properly validate codebase URLs provided within Common Data Representation (CDR) streams.\u003c/p\u003e\n\u003cp\u003eAn unauthenticated remote attacker can supply a malicious URL containing a crafted class definition. Because this process occurs before EJB security interceptors are initialized, the server JVM will load and instantiate arbitrary classes from the remote location, leading to Remote Code Execution (RCE). This vulnerability is particularly dangerous as it bypasses standard EJB-level security controls, effectively granting the attacker the privileges of the JBoss application server process.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for full remote code execution within the context of the JBoss EAP server process. This can lead to total system compromise, unauthorized data access, and lateral movement within the enterprise network. Organizations running EAP instances with the '-secmgr' configuration are at the highest risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all JBoss EAP instances currently running with the '-secmgr' flag in your environment.\u003c/li\u003e\n\u003cli\u003eApply the vendor-provided patch or update to the version of JBoss EAP that addresses CVE-2026-15560.\u003c/li\u003e\n\u003cli\u003eMonitor network traffic directed to port 3528 for unexpected outbound connections from the JBoss server to external hosts, which may indicate an attempt to fetch remote class files for instantiation.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-11T09:49:53Z","date_published":"2026-08-11T09:48:47Z","id":"https://feed.craftedsignal.io/briefs/2026-08-jboss-eap-cve-2026-15560/","summary":"CVE-2026-15560 allows unauthenticated remote code execution in Red Hat JBoss EAP environments configured with the -secmgr flag due to insecure object unmarshalling.","title":"Unauthenticated Remote Code Execution in Red Hat JBoss EAP via openjdk-orb","url":"https://feed.craftedsignal.io/briefs/2026-08-jboss-eap-cve-2026-15560/"}],"language":"en","title":"CraftedSignal Threat Feed - Enterprise-Application","version":"https://jsonfeed.org/version/1.1"}