Skip to content
Threat Feed

Vendor

Apache

69 briefs RSS
critical advisory

Unauthenticated Arbitrary File Write in Apache Kyuubi REST API

An unauthenticated path-traversal vulnerability in the Apache Kyuubi REST API (CVE-2026-52680) allows remote attackers to write arbitrary files to the filesystem, leading to remote code execution.

Apache Kyuubi
1r 2t
medium advisory

Apache HttpComponents Denial of Service Vulnerability

A vulnerability in Apache HttpComponents allows a remote, unauthenticated attacker to trigger a Denial of Service condition on targeted applications.

HttpComponents
1t
medium advisory

Detection of Unauthorized Apache Thrift RPC Invocations from External Networks

Detection logic targeting unauthorized Apache Thrift RPC method invocations from external IP addresses to identify exposed internal microservices or potential exploitation of data platforms.

Thrift network-security initial-access microservices
1r 1t 1c
high advisory

Apache Cassandra JavaScript User-Defined Function Execution

Adversaries can exploit the creation of JavaScript-based user-defined functions in Apache Cassandra to escape the Nashorn sandbox and achieve remote code execution, particularly when vulnerable to CVE-2021-44521.

Cassandra vulnerability execution cql sandbox-escape
1r 1t 1c
medium advisory

Apache Tomcat Denial of Service Vulnerability (CVE-2026-66299)

A critical vulnerability, CVE-2026-66299, has been discovered in Apache Tomcat versions 9.0.x prior to 9.0.121, 10.1.x prior to 10.1.58, and 11.0.x prior to 11.0.25, allowing a remote attacker to cause a denial of service (DoS).

Apache Tomcat +2 denial-of-service vulnerability apache-tomcat
1t 1c 4i
medium advisory

Apache Tomcat Vulnerability Allows Denial of Service

A vulnerability in Apache Tomcat allows a remote, anonymous attacker to perform a Denial of Service attack, potentially disrupting service availability for applications hosted on the affected server.

Apache Tomcat denial-of-service vulnerability apache
1t
high threat

Multiple Vulnerabilities in Apache Traffic Server

Multiple vulnerabilities in Apache Traffic Server can be exploited by a remote, anonymous attacker to bypass security measures, disclose or manipulate data, trigger a denial-of-service, and potentially achieve code execution.

exploited Apache Traffic Server web-vulnerability rce dos data-manipulation apache
2t
critical advisory

Apache Axis2: Vulnerability Allows Code Execution

An anonymous, remote attacker can exploit a vulnerability in Apache Axis2 to execute arbitrary program code. This flaw allows for critical remote code execution without authentication, posing a significant risk to systems running the affected software.

Axis2 remote-code-execution vulnerability-exploitation apache
2t
high threat

Multiple Vulnerabilities Identified in Apache Thrift

Multiple vulnerabilities, including decompression bombs (CVE-2026-48586, CVE-2026-49158), an integer overflow (CVE-2026-55969), and a heap out-of-bounds read (CVE-2026-58023), affect Apache Thrift prior to version 0.24.0, potentially leading to denial of service, memory corruption, or arbitrary code execution, and require immediate patching.

exploited Apache Thrift vulnerability apache library
4c
critical advisory

Apache Airflow FAB Provider Vulnerability Allows Obtaining Administrator Rights

An unauthenticated, remote attacker can exploit a vulnerability in Apache Airflow FAB provider to bypass security measures and escalate privileges to gain administrator rights, allowing full control of the affected system.

Airflow FAB provider privilege-escalation defense-evasion web-application apache airflow
2t
medium advisory

Multiple Vulnerabilities in Apache Wicket Allow XSS and Security Bypass

An anonymous, remote attacker can exploit multiple vulnerabilities in Apache Wicket to perform Cross-Site Scripting (XSS) attacks and bypass existing security measures, potentially leading to unauthorized client-side script execution and further compromise of user sessions or data.

Wicket vulnerability web-application xss security-bypass
2t
high advisory

Web Server Outbound Connections to File Sharing Services

Attackers compromise web servers (Apache, Nginx, Tomcat, PHP) and leverage them to make unexpected outbound network connections to public file-sharing or content hosting services, indicating post-exploitation activity for ingress tool transfer and further compromise.

Apache HTTP Server +3 post-exploitation ingress-tool-transfer webshell web-server c2 windows
1r 2t 26i
medium advisory

Apache Tomcat mod_jk Connector: Vulnerability Enables Security Bypass or Information Disclosure

A vulnerability in the Apache Tomcat mod_jk Connector allows a remote, unauthenticated attacker to bypass security measures or disclose sensitive information, which could enable an adversary to gain unauthorized access or collect confidential data.

Tomcat mod_jk Connector defense-evasion network vulnerability
2t
high advisory

Public Exploit for Apache Camel CVE-2026-49098 Improper Input Validation

A public exploit has been released for CVE-2026-49098, an improper input validation vulnerability in Apache Camel's 'camel-kafka' component, which allows an attacker to perform message-header injection by supplying 'kafka.OVERRIDE_TOPIC' in HTTP headers, enabling cross-topic message injection and integrity compromise of sensitive Kafka topics.

Apache Camel +2 apache-camel vulnerability kafka injection
1t 1c
low advisory

Web Server Local File Inclusion Activity

This brief details how attackers exploit Local File Inclusion (LFI) vulnerabilities on web servers such as Nginx, Apache, IIS, and Traefik, by using directory traversal or direct sensitive file path requests to disclose system information, credentials, and configuration files, potentially leading to remote code execution and system compromise.

Nginx +4 local-file-inclusion web-vulnerability information-disclosure remote-code-execution discovery
1r 4t 1i
critical threat

CVE-2026-63030: Critical Remote Code Execution Vulnerability in WordPress Core

CVE-2026-63030 is a critical unauthenticated remote code execution vulnerability affecting WordPress Core versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1, allowing an unauthenticated attacker to execute arbitrary code via the WordPress REST API batch endpoint, potentially leading to complete website compromise.

exploited PoC WordPress Core 6.9.0 +51 wordpress rce web-vulnerability cve
2t 15c 8i updated
medium advisory

Apache Ivy: Vulnerability Allows File Manipulation

A remote, authenticated attacker can exploit a vulnerability in Apache Ivy to manipulate files on the system, leading to unauthorized modification of data and potential integrity compromise.

Apache Ivy file-manipulation vulnerability
1t
critical threat

Qilin Ransomware Claims New Victim in Agriculture and Food Production Sector

The Qilin ransomware group, active since July 2022 and utilizing Golang, has claimed a new victim, Danone (International Delights) in the US Agriculture and Food Production sector, employing double extortion tactics involving data encryption and threatened data release.

www.acosol.es +42 Qilin +1 ransomware double-extortion golang agriculture food-production
2r 13t 156i updated
high threat

Multiple Vulnerabilities in Apache Tomcat

Multiple vulnerabilities, including CVE-2026-59083 and CVE-2026-59084, have been discovered in Apache Tomcat versions 10.1.x prior to 10.1.57, 11.0.x prior to 11.0.24, and 9.0.x prior to 9.0.120, allowing an attacker to bypass security policies and cause an unspecified security issue.

exploited Tomcat 10.1.x +2 vulnerability apache tomcat web-server
1t 2c
medium advisory

Apache ActiveMQ Cross-Site Scripting Vulnerability

A remote, authenticated attacker can exploit a Cross-Site Scripting (XSS) vulnerability in Apache ActiveMQ to execute malicious scripts within a victim's browser.

ActiveMQ xss web-vulnerability apache
1t
high advisory

Multiple Vulnerabilities in Apache Airflow Allow Privilege Escalation

An attacker can exploit multiple vulnerabilities in Apache Airflow to bypass security controls and escalate their privileges, as reported by CERT-Bund.

Apache Airflow defense-evasion privilege-escalation apache airflow
1t
critical advisory

Exploitation of CVE-2026-44747 in SAP NetWeaver ABAP via Memory Corruption

An authenticated attacker can exploit CVE-2026-44747, an out-of-bounds write vulnerability in SAP NetWeaver Application Server ABAP, to cause memory corruption leading to unauthorized data access, modification, or system unavailability, severely impacting confidentiality, integrity, and availability.

SAP NetWeaver Application Server ABAP +25 cve-2026-44747 memory-corruption sap netweaver abap out-of-bounds-write
4t 3c updated
high advisory

Multiple Vulnerabilities in Apache Camel Lead to Arbitrary Code Execution

Multiple vulnerabilities exist in Apache Camel that an attacker can exploit to bypass security controls and execute arbitrary program code, potentially leading to system compromise and unauthorized operations.

Apache Camel vulnerability apache camel code-execution security-bypass
1t
medium advisory

AWS Lambda Event Source Mapping Abuse for Persistence and Data Exfiltration

Adversaries can exploit the creation of AWS Lambda event source mappings to establish stealthy persistence and execution, or to continuously siphon records from event sources like Amazon SQS, Kinesis, DynamoDB, MSK, Kafka, or MQ, by mapping an event source to an attacker-controlled Lambda function, enabling durable execution and data exfiltration without requiring further interactive access.

AWS Lambda +6 cloud aws persistence execution data-exfiltration
1r 3t
high advisory

Multiple Vulnerabilities Discovered in SAP Products Including SQLi, XSS, and Policy Bypass

Multiple high-severity vulnerabilities discovered in various SAP products, including SQL injection (SQLi), remote indirect code injection (XSS), and security policy bypasses, could allow unauthenticated attackers to compromise sensitive enterprise systems by June 2026.

Business Objects Business Intelligence Platform +86 sap vulnerability sqli xss web-application
2r 5t 5i updated
medium threat

Unusual Child Process Execution from Linux Web Servers

This rule detects unusual child process executions originating from web server processes on Linux systems, which attackers may use to maintain persistence on a compromised system by exploiting web server vulnerabilities.

Jira +20 persistence execution command_and_control initial_access linux webserver
2r 4t
medium threat

Suspicious Command Execution via Web Server on Linux

Identifies suspicious command executions via a web server on Linux systems, which may suggest a vulnerability and remote shell access.

Elastic Defend +43 persistence initial-access vulnerability linux
2r 3t
medium advisory

Suspicious Command Execution via Web Server on Linux

Identifies suspicious command executions via a web server on Linux systems, potentially indicating a vulnerability exploitation or remote shell access for persistence.

Elastic Defend endpoint linux persistence initial-access vulnerability
3r 2t
low advisory

Unusual Command Execution from Web Server Parent Process on Linux

This rule detects potential command execution from a web server parent process on a Linux host, indicating a possible web shell attack where adversaries exploit web server vulnerabilities to execute arbitrary commands.

Elastic Defend +2 web-shell command-execution persistence linux
2r 3t
critical advisory

Apache CouchDB Improper Privilege Management Leads to Remote Code Execution

A public exploit demonstrates improper privilege management in Apache CouchDB (CVE-2017-12635) leading to privilege escalation, which can be combined with CVE-2017-12636 for remote code execution by modifying server configurations via the HTTP API.

CouchDB 1.6.0 privilege-escalation remote-code-execution couchdb CVE-2017-12635 CVE-2017-12636
2r 2t 2c
medium threat

Apache Tika Vulnerability Allows Information Disclosure or Manipulation

A remote, anonymous attacker can exploit a vulnerability in Apache Tika to read sensitive data or trigger malicious requests to internal resources or third-party servers.

Tika apache-tika vulnerability infoleak
2r 1t
critical threat

Critical Deserialization Vulnerability in Apache ActiveMQ NMS AMQP Client (CVE-2025-54539)

A critical deserialization of untrusted data vulnerability (CVE-2025-54539) exists in Apache ActiveMQ NMS AMQP Client <= v2.3.0, where an attacker controlling or impersonating an AMQP broker can send malicious serialized data that the client deserializes unsafely, allowing arbitrary code execution on the client system.

ActiveMQ NMS AMQP Client <= v2.3.0 deserialization rce activemq cve-2025-54539 windows
2r 1t 1c
high advisory

CVE-2026-44930: Apache CXF LDAP Injection Vulnerability

CVE-2026-44930 is an LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF that may allow an attacker to retrieve arbitrary certificates from the repository.

CXF ldap-injection cve web-application
2r 1t 1c
medium advisory

Apache Tomcat Security Bypass Vulnerability

A remote, anonymous attacker can exploit a vulnerability in Apache Tomcat to bypass security measures.

Tomcat apache security-bypass
2r 1t
high advisory

Multiple Vulnerabilities in Apache OFBiz

Multiple vulnerabilities in Apache OFBiz could allow an attacker to execute arbitrary code, circumvent security measures, manipulate data, disclose confidential information, or conduct cross-site scripting attacks.

OFBiz vulnerability apache-ofbiz code-execution xss
2r 9t
critical advisory

Apache Axis 1.4 Server-Side Request Forgery Vulnerability (CVE-2019-0227) Exploit

A public exploit has been released for CVE-2019-0227, a Server-Side Request Forgery vulnerability in Apache Axis 1.4 and earlier, allowing unauthenticated remote command execution when `enableRemoteAdmin` is true via deployment of a malicious webservice and webshell.

Axis ssrf rce apache
2r 2t 1c 1i
high advisory

Multiple Vulnerabilities in Apache Camel

Multiple vulnerabilities in Apache Camel could allow an attacker to execute arbitrary code, manipulate data, or disclose sensitive information.

Camel apache-camel vulnerability code-execution data-manipulation information-disclosure
3r 2t
critical threat

Apache Camel Vulnerability Allows Remote Code Execution

A remote, anonymous attacker can exploit a vulnerability in Apache Camel to execute arbitrary program code with the privileges of the service.

Camel-Coap remote-code-execution apache-camel
2r 1t
high advisory

Multiple Vulnerabilities in Apache Solr

Multiple vulnerabilities in Apache Solr could be exploited by an attacker to bypass security measures, manipulate data, and disclose sensitive information.

Solr apache-solr vulnerability data-breach defense-evasion
2r 3t
high advisory

Siemens Opcenter RDnL Missing Authentication Vulnerability (CVE-2026-27446)

Siemens Opcenter RDnL is vulnerable to missing authentication in critical function (CVE-2026-27446), where an unauthenticated attacker can use the Core protocol to force a target broker to establish an outbound Core federation connection to an attacker-controlled rogue broker, potentially leading to availability impacts and message injection.

Opcenter RDnL +1 cve vulnerability siemens activemq
2r 1t 1c
critical advisory

Apache HertzBeat 1.8.0 Remote Code Execution Vulnerability

Apache HertzBeat 1.8.0 is vulnerable to remote code execution due to a newly published exploit, posing a significant risk to unpatched systems.

HertzBeat 1.8.0 rce apache-hertzbeat exploit webapps
2r 1t
high advisory

Apache Cassandra Vulnerability Allows Code Execution

A local attacker can exploit a vulnerability in Apache Cassandra to execute arbitrary program code, potentially leading to complete system compromise.

Cassandra apache rce
2r 1t
medium advisory

Apache Airflow Providers OpenSearch and Elasticsearch Information Disclosure Vulnerabilities

A remote, authenticated attacker can exploit multiple vulnerabilities in Apache Airflow Providers OpenSearch and Elasticsearch to disclose sensitive information.

Airflow Providers OpenSearch +1 airflow information-disclosure apache
1r 1t
high advisory

Apache NiFi Vulnerability Allows Remote Code Execution

A vulnerability in Apache NiFi allows a remote attacker to execute arbitrary program code on the affected system.

NiFi apache-nifi rce code-execution
2r 1t
critical threat

Apache NiFi Multiple Vulnerabilities Allow Remote Code Execution

An authenticated, remote attacker can exploit multiple vulnerabilities in Apache NiFi to execute arbitrary code and achieve unspecified impacts.

Nifi apache-nifi rce vulnerability
2r
low advisory

Apache Airflow OpenSearch Provider Credentials Leak via Task Logs (CVE-2026-43826)

The OpenSearch logging provider in Apache Airflow Providers OpenSearch versions before 1.9.1 wrote host URLs containing embedded credentials into task logs, potentially exposing them to unauthorized users with task-log read permission (CVE-2026-43826).

Airflow Providers OpenSearch credential-leak airflow opensearch
2r
critical advisory

Apache HTTP Server HTTP/2 Protocol Vulnerability Could Allow for Remote Code Execution

A vulnerability in Apache HTTP Server's HTTP/2 protocol can lead to denial of service by crashing worker processes, and in specific configurations (APR with mmap), remote code execution.

HTTP Server apache http2 rce dos webserver
2r 2t
high advisory

Multiple Vulnerabilities in Apache Wicket

Multiple vulnerabilities in Apache Wicket could allow an attacker to bypass security measures, perform Cross-Site Scripting (XSS) attacks, disclose confidential information, or manipulate data.

Wicket apache-wicket xss vulnerability
2r 2t
critical threat

Multiple Vulnerabilities in Apache HTTP Server

Multiple vulnerabilities in Apache HTTP Server can be exploited by an attacker to gain elevated privileges, execute arbitrary code, bypass security measures, disclose sensitive information, or cause a denial-of-service condition.

HTTP Server apache vulnerability privilege-escalation execution defense-evasion information-disclosure denial-of-service
2r 6t
critical advisory

Multiple Vulnerabilities in Apache HTTP Server Allow Remote Code Execution, Privilege Escalation, and Denial of Service

Multiple vulnerabilities in Apache HTTP Server versions prior to 2.4.67 can allow remote attackers to execute arbitrary code, escalate privileges, or cause a denial of service.

HTTP Server apache http vulnerability rce privilege-escalation dos
3r 3t 5c
critical advisory

Apache MINA Arbitrary Code Execution Vulnerability

A critical arbitrary code execution vulnerability (CVE-2026-41635) exists in Apache MINA versions 2.0.0 through 2.0.27, 2.1.0 through 2.1.10, and 2.2.0 through 2.2.5 due to missing class validation in the AbstractIoBuffer.resolveClass() method, potentially allowing attackers to execute arbitrary code on applications using Apache MINA.

MINA 2.0 +2 apache-mina rce deserialization cve-2026-41635
2r 1t 1c
critical advisory

BridgeHead FileStore Unauthenticated Remote Code Execution via Apache Axis2

BridgeHead FileStore versions prior to 24A are vulnerable to unauthenticated remote code execution via exposed Apache Axis2 administration module with default credentials, enabling attackers to upload malicious web services and execute arbitrary OS commands.

FileStore +1 rce cve-2026-39920 apache axis2 default credentials web service
2r 2t 1c
critical advisory

Apache ActiveMQ Vulnerabilities Allow RCE and XSS

An authenticated remote attacker can exploit multiple vulnerabilities in Apache ActiveMQ to execute arbitrary program code or perform cross-site scripting attacks.

ActiveMQ rce xss apache
2r 1t 5c
critical threat

Critical RCE Vulnerability in Langflow AI Pipelines (CVE-2026-33017)

A critical remote code execution vulnerability, CVE-2026-33017, exists in Langflow AI pipelines prior to version 1.9.0 that allows an unauthenticated remote attacker to execute code with full server process privileges, impacting availability, integrity, and confidentiality.

Siyuan +6 langflow rce cve-2026-33017 ai-pipeline
2r 2t 1i updated
critical advisory

Apache Tomcat Vulnerability Allows Remote Code Execution

An anonymous, remote attacker can exploit an unspecified vulnerability in Apache Tomcat to achieve arbitrary code execution.

Apache Tomcat apache-tomcat rce vulnerability
2r 1t
medium advisory

Web Server Local File Inclusion Activity Detected

Detection of potential Local File Inclusion (LFI) activity on web servers through HTTP GET requests attempting to access sensitive local files via directory traversal or known file paths, potentially leading to information disclosure and system compromise.

Nginx +4 web-server lfi file-inclusion discovery credential-access initial-access
3r 4t
low advisory

Potential HTTP Downgrade Attack Detected

The new_terms rule detects potential HTTP downgrade attacks by identifying HTTP traffic using a different HTTP version than typically used, potentially exposing systems to vulnerabilities in older protocols.

Nginx +3 defense-evasion http-downgrade web-server
2r 1t
medium advisory

Apache Tomcat Security Bypass Vulnerability

A remote, anonymous attacker can exploit an unspecified vulnerability in Apache Tomcat to bypass security measures, potentially leading to unauthorized access or modification of data.

Apache Tomcat apache-tomcat security-bypass defense-evasion
2r 1t
low advisory

Web Server Error Response Spike Indicating Reconnaissance

An unusual spike in web server error codes (500, 502, 503, 504) may indicate reconnaissance activities like vulnerability scanning or fuzzing, where attackers probe for weaknesses, potentially leading to exploitation of server-side issues.

Nginx +4 web-server reconnaissance vulnerability-scanning fuzzing
2r 2t
high advisory

Web Shell Activity Detection via Process Monitoring

This brief focuses on detecting malicious activity related to web shells on Windows systems by identifying the execution of command interpreters and scripting engines as child processes of common web server processes, potentially indicating unauthorized command execution and persistent access.

Windows +3 webshell persistence initial-access execution
2r 4t
low advisory

Web Server Remote File Inclusion Activity Detected

This rule detects potential Remote File Inclusion (RFI) activity on web servers by identifying HTTP GET requests that attempt to access sensitive remote files through directory traversal techniques or known file paths to read sensitive files, gain system information, or further compromise the server.

Nginx +4 remote-file-inclusion web-server discovery
2r 1t
low advisory

Web Server Discovery or Fuzzing Activity Detection

This rule detects potential web server discovery or fuzzing activity by identifying a high volume of HTTP GET requests resulting in 404 or 403 status codes from a single source IP address within a short timeframe, indicating attackers discovering hidden resources for targeted attacks.

Nginx +4 web-server fuzzing reconnaissance web
2r 2t
high advisory

Apache Struts CVE-2023-50164 Exploitation Leading to Web Shell Deployment

Exploitation of CVE-2023-50164, a critical path traversal vulnerability in Apache Struts 2, is detected by identifying malicious multipart/form-data POST requests with WebKitFormBoundary targeting Struts .action upload endpoints, followed by JSP web shell creation in Tomcat's webapps directories, indicating remote code execution.

Struts 2 apache-struts webshell cve-2023-50164 initial-access persistence command-and-control
2r 3t 1c
low advisory

Web Server Potential Command Injection Request

The rule detects potential command injection attempts via web server requests by identifying URLs that contain suspicious patterns commonly associated with command execution payloads.

Nginx +4 web-server command-injection persistence
2r 5t
medium advisory

Web Server Request Command Injection Attempt

Detection of potential command injection attempts via web server requests by identifying URLs containing suspicious patterns associated with command execution payloads, which attackers exploit to execute arbitrary commands on the server.

Apache +4 command-injection web-server persistence
2r 5t
low advisory

Web Server Reconnaissance via Unusual User Agents

Detection of unusual spikes in web server requests with uncommon or suspicious user-agent strings indicative of reconnaissance attempts to identify web application vulnerabilities or brute-force attacks.

Nginx +4 web-server reconnaissance vulnerability-scanning user-agent
2r 4t
high advisory

OpenMRS ModuleResourcesServlet Path Traversal Vulnerability

OpenMRS Core versions 2.7.8 and earlier, as well as versions 2.8.0 through 2.8.5, contain a path traversal vulnerability in the ModuleResourcesServlet, allowing an unauthenticated attacker to read arbitrary files from the server filesystem by manipulating the URL.

Tomcat +2 path-traversal information-disclosure openmrs
2r 1t
medium advisory

Web Server Local File Inclusion Activity

This rule detects potential Local File Inclusion (LFI) exploitation on web servers by identifying HTTP GET requests attempting to access sensitive local files through directory traversal or known file paths, potentially leading to sensitive information disclosure.

Nginx +4 lfi web-server directory-traversal information-disclosure
2r 1t
low advisory

Web Server Discovery or Fuzzing Activity

Detection of potential web server discovery or fuzzing activity characterized by a high volume of HTTP GET requests resulting in 404 or 403 status codes originating from a single source IP address within a short timeframe, indicating attackers are probing for hidden resources.

Nginx +4 reconnaissance web-server fuzzing
2r 2t