Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · apache

apache

· 421 Critical

Total CVEs

3,068

Critical

421

Products

381

Search All CVEs →

3,068

Products (381)

http server347 CVEstomcat257 CVEsairflow121 CVEstraffic server120 CVEsstruts91 CVEsofbiz76 CVEssuperset70 CVEsopenoffice61 CVEsactivemq59 CVEscxf57 CVEsnifi49 CVEssubversion48 CVEssolr46 CVEscloudstack45 CVEscamel40 CVEshadoop37 CVEsinlong32 CVEsthrift32 CVEsjspwiki29 CVEsopenmeetings28 CVEsdolphinscheduler27 CVEsambari26 CVEstika25 CVEszeppelin25 CVEswicket24 CVEssyncope24 CVEsgeode23 CVEsshiro23 CVEsspark22 CVEskylin21 CVEsranger21 CVEscouchdb20 CVEsarchiva20 CVEspulsar20 CVEsfineract20 CVEshive20 CVEsdubbo19 CVEslog4j19 CVEslinkis18 CVEscordova18 CVEsanswer17 CVEsiotdb17 CVEsstreampark17 CVEshertzbeat16 CVEscassandra16 CVEsqpid16 CVEskafka15 CVEsartemis15 CVEsnimble15 CVEsroller14 CVEsjames14 CVEsstorm14 CVEsjmeter14 CVEsatlas14 CVEsapisix13 CVEsspamassassin13 CVEsguacamole13 CVEskaraf12 CVEsdruid12 CVEsozone11 CVEsbatik11 CVEscommons compress11 CVEsxerces-c\+\+11 CVEsgeronimo11 CVEszookeeper11 CVEstapestry10 CVEstomee10 CVEspdfbox10 CVEspoi10 CVEsmesos9 CVEsnuttx9 CVEsignite9 CVEsshenyu9 CVEsportable runtime9 CVEshttpclient8 CVEsqpid broker-j8 CVEstraffic control8 CVEsderby8 CVEsmina7 CVEsimpala7 CVEsstreampipes7 CVEsavro7 CVEsaxis7 CVEsbookkeeper7 CVEsjetspeed6 CVEssantuario xml security for java6 CVEsdoris6 CVEsjackrabbit6 CVEsjuddi6 CVEsmina sshd6 CVEssling6 CVEspluto6 CVEsjena6 CVEscxf fediz6 CVEsxml security for c\+\+6 CVEsallura6 CVEsdrill6 CVEscommons configuration6 CVEsactivemq broker6 CVEsaxis26 CVEscommons fileupload6 CVEsmod python6 CVEshbase6 CVEsapr-util6 CVEsbrpc6 CVEsneethi6 CVEsfory6 CVEsopennlp5 CVEsmyfaces5 CVEsseata5 CVEssubmarine5 CVEstomcat native5 CVEsapache-airflow-providers-apache-hive5 CVEsarrow5 CVEscocoon5 CVEswss4j5 CVEspolaris4 CVEsrocketmq4 CVEscommons beanutils4 CVEspony mail4 CVEsskywalking4 CVEssling cms4 CVEspinot4 CVEssshd4 CVEsapache-airflow-providers-fab4 CVEsopenoffice.org4 CVEsoozie4 CVEsflink4 CVEsolingo4 CVEsjames server4 CVEskvrocks4 CVEsant4 CVEshugegraph4 CVEsnetbeans4 CVEsany234 CVEslog4cxx4 CVEsmod fcgid4 CVEsunomi3 CVEsservicecomb3 CVEsseatunnel3 CVEsivy3 CVEskyuubi3 CVEsvcl3 CVEsgroovy3 CVEslibapreq23 CVEslibcloud3 CVEsbrooklyn3 CVEsmod perl3 CVEsvirtual computing lab3 CVEstomcat connectors3 CVEsuimaj3 CVEsapache-airflow-providers-apache-spark3 CVEsapache-airflow-providers-google3 CVEstomcat jk connector3 CVEsxerces2 java3 CVEshelix3 CVEsheron3 CVEslog4net3 CVEsshardingsphere3 CVEslivy3 CVEsflume3 CVEsaccumulo2 CVEsactivemq all2 CVEsactivemq web2 CVEsairflow cncf kubernetes2 CVEsapache-airflow-providers-amazon2 CVEsapache-airflow-providers-apache-drill2 CVEsapache-airflow-providers-mysql2 CVEsapache-airflow-providers-odbc2 CVEsapisix dashboard2 CVEsaurora2 CVEsbeam2 CVEscalcite2 CVEscayenne2 CVEschainsaw2 CVEscommons email2 CVEscommons imaging2 CVEscommons io2 CVEscommons jxpath2 CVEscommons vfs2 CVEscontinuum2 CVEscordova file transfer2 CVEsdeltaspike2 CVEsdirectory ldap api2 CVEsdirectory studio2 CVEsdoris mcp server2 CVEseventmesh2 CVEsformatting objects processor2 CVEsgobblin2 CVEshttpcomponents core2 CVEsisis2 CVEsknox2 CVEsmaven2 CVEsmod jk2 CVEsmxnet2 CVEsnifi minifi c\+\+2 CVEsnifi registry2 CVEsnutch2 CVEsopenwhisk2 CVEsorc2 CVEsorg.apache.sling.servlets.post2 CVEsparquet java2 CVEsportable runtime utility2 CVEsqpid-cpp2 CVEsqpid proton2 CVEssentry2 CVEsshardingsphere elasticjob-ui2 CVEssling api2 CVEssling servlets post2 CVEssoap2 CVEssynapse2 CVEstiles2 CVEstomcat jk web server connector2 CVEsuimaducc2 CVEsws-xmlrpc2 CVEsxalan-java2 CVEsxerces-j2 CVEsxml-rpc2 CVEsxml graphics batik2 CVEsmanifoldcf1 CVEstuscany1 CVEsmaven archetype1 CVEsmaven shared utils1 CVEsmaven wagon1 CVEshttp server2.0a51 CVEshttp server2.0a41 CVEshttp server2.0a31 CVEsmod-gnutls1 CVEsmod auth radius1 CVEsmod dav svn1 CVEsmod dontdothat1 CVEshttp server2.0a21 CVEsuima-as1 CVEshttp server2.0a11 CVEshtml\/java api1 CVEsactivemq amqp1 CVEshop engine1 CVEsmyfaces tomahawk1 CVEsmyfaces trinidad1 CVEsharmony1 CVEshama1 CVEsgroovy ldap1 CVEsuimafit1 CVEsairflow hive provider1 CVEsfortress1 CVEsuniffle1 CVEsflink stateful functions1 CVEsode1 CVEsflink kubernetes operator1 CVEsflink cdc1 CVEsflex blazeds1 CVEsopenjpa1 CVEsflex1 CVEsfelix webconsole1 CVEsfelix http webconsole plugin1 CVEsfelix health check webconsole plugin1 CVEsopentaps1 CVEsairflow hdfs provider1 CVEsunstructured information management architecture1 CVEsorchestration director engine1 CVEsairflow common sql provider1 CVEseventmesh-connector-rabbitmq1 CVEsparquet1 CVEsvelocity engine1 CVEsecharts1 CVEspekko management1 CVEsddlutils1 CVEsplc4x1 CVEscordova inappbrowser1 CVEscordova in-app-browser1 CVEscommons text1 CVEscommons ognl1 CVEscommons net1 CVEsvelocity tools1 CVEscommons lang1 CVEspulsar manager1 CVEspyarrow1 CVEscommons jelly1 CVEsairflow celery provider1 CVEscommons collections1 CVEsqpid dispatch1 CVEsairavata django portal1 CVEsqpid proton-j1 CVEsrampart\/c1 CVEscommons bcel1 CVEsrave1 CVEscommons-httpclient1 CVEscauseway1 CVEsrust sgx sdk1 CVEsaxis2\/java1 CVEsasterixdb1 CVEsapache webserver1 CVEswink1 CVEsapache sling engine1 CVEsapache http server1 CVEsshardingsphere-ui1 CVEsactivemq legacy openwire module1 CVEsapache commons daemon1 CVEsshindig1 CVEsapache calcite avatica1 CVEsapache axis2\/c1 CVEsskywalking mcp1 CVEsskywalking nodejs agent1 CVEsapache-airflow-providers-snowflake1 CVEsage1 CVEssling auth core component1 CVEssling authentication service1 CVEsapache-airflow-providers-smtp1 CVEssling commons json1 CVEssling commons log1 CVEssling commons messaging mail1 CVEssling i18n1 CVEssling jcr base1 CVEssling jcr contentloader1 CVEssling resource merger1 CVEsxmlbeans1 CVEssling servlets resolver1 CVEssling xss protection api1 CVEssling xss protection api compat1 CVEsactivemq nms openwire1 CVEsapache-airflow-providers-samba1 CVEssolr operator1 CVEsapache-airflow-providers-opensearch1 CVEsapache-airflow-providers-mongo1 CVEsspatial information system1 CVEsapache-airflow-providers-microsoft-mssql1 CVEssshj1 CVEsstandard taglibs1 CVEsapache-airflow-providers-keycloak1 CVEsstorm prometheus reporter1 CVEsapache-airflow-providers-jdbc1 CVEsapache-airflow-providers-imap1 CVEsapache-airflow-providers-ftp1 CVEsstruts2-showcase1 CVEsstruts extras1 CVEsapache-airflow-providers-elasticsearch1 CVEsapache-airflow-providers-edge31 CVEsapache-airflow-providers-docker1 CVEsxmlgraphics commons1 CVEsapache-airflow-providers-cncf-kubernetes1 CVEssystemds1 CVEsapache-airflow-providers-apache-sqoop1 CVEsteaclave sgx sdk1 CVEsapache-airflow-providers-apache-pinot1 CVEsapache-airflow-providers-apache-pig1 CVEsactivemq nms amqp1 CVEsapache1 CVEsamqp 0-x jms client1 CVEsairflow sqoop provider1 CVEsactivemq apollo1 CVEsairflow spark provider1 CVEsairflow providers http1 CVEsairflow providers databricks1 CVEsjena sdb1 CVEsjena fuseki1 CVEsjms client amqp1 CVEsjohnzon1 CVEsjserv1 CVEsjclouds1 CVEsjava chassis1 CVEsjames mime4j1 CVEskafka connect1 CVEsjakarta slide1 CVEskaraf cave1 CVEskaraf decanter1 CVEskerby ldap backend1 CVEsairflow providers amazon1 CVEskudu1 CVEsjackrabbit oak1 CVEsiotdb workbench1 CVEsiotdb web workbench1 CVEsldap studio1 CVEshupa1 CVEshugegraph-hubble1 CVEshttpasyncclient1 CVEshttp server2.0a91 CVEshttp server2.0a81 CVEshttp server2.0a71 CVEshttp server2.0a61 CVEslucene.net1 CVEslucene replicator1 CVEs

Recent Vulnerabilities

View all 3,068
CVE-2026-68981HIGH 7.5

Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding filter. The framework enforced a configurable maximum request size on the compressed payload rather than the decompressed output, allowing a malicious client to send crafted requests that could consume excessive amounts of memory. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, which relocates response compression to Jetty Server and disables decompression of gzip-encoded HTTP requests.

CVE-2026-68980CRITICAL 9.1

Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API. The framework authorizes asset deletion against the owning Parameter Context using the supplied Parameter Context Identifier and Asset Identifier. The framework performed authorized based on the supplied Parameter Context Identifier without verifying the requested Identifier against the stored Identifier. Apache NiFi installations that do not implement different levels of authorization across Parameter Contexts are not subject to this vulnerability, because the framework enforces write permissions as the security boundary. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, which verifies Parameter Context ownership of the requested Asset before deletion using the same strategy applied to Asset read operations.

CVE-2026-68979CRITICAL 9.8

Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization checking on components referencing Parameter values. Updating a Parameter Context can change parameter values that affect referencing components, but framework authorization was limited to read and write privileges on the Parameter Context itself. As a result of the missing authorization, an authenticated user authorized to modify a Parameter Context, but not authorized on referencing components, could alter Parameter values affecting those components. In deployments where a Parameter value contains executable scripting content, updating a Parameter can result in code execution during automatic component validation, without starting the referencing component. The impact was limited to stopped components by existing verification checks, and the issue applies only to deployments that use component-level authorization policies. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, which aligns the Parameter Context update method authorization with other methods, adding authorization checking on affected components.

CVE-2026-52680CRITICAL 9.8

Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary uploaded resource. A remote attacker who can access the REST batch upload endpoint can provide path traversal sequences in the filename and cause the Kyuubi server process to write controlled content outside the intended upload directory, subject to filesystem permissions. This issue affects Apache Kyuubi: from 1.7.0 through 1.11.1. Users are recommended to upgrade to version 1.12.0, which fixes the issue.

CVE-2026-48910MEDIUM 6.5

A carefully crafted editing request could trigger an XSS vulnerability on Apache JSPWiki when parsing errors on the markdown renderer, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. This issue affects Apache JSPWiki: through 2.12.3. Users are recommended to upgrade to version 2.12.4, which fixes the issue.

CVE-2026-44617MEDIUM 6.5

LDAP filter injection vulnerability in Apache Zeppelin. LdapRealm used RFC 4514 distinguished-name escaping when constructing LDAP search filters instead of RFC 4515 filter escaping, leaving special filter characters insufficiently escaped.                   This is an incomplete fix of CVE-2024-31867. This issue affects Apache Zeppelin versions 0.11.1, 0.11.2, and 0.12.0. Users are recommended to upgrade to version 0.12.1, which fixes this issue.

CVE-2026-44616MEDIUM 6.5

LDAP injection vulnerability in Apache Zeppelin. ActiveDirectoryGroupRealm constructed LDAP search filters without escaping user-controlled input, allowing an authenticated attacker to inject LDAP filter syntax through the user-search endpoint                   and potentially expose directory information. The role-lookup path was also affected after successful LDAP authentication. This issue affects Apache Zeppelin versions 0.6.0 through 0.12.0. Users are recommended to upgrade to version 0.12.1, which                   fixes this issue.

CVE-2026-44613MEDIUM 6.1

Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin. The default CORS configuration allowed cross-origin state-changing requests and accepted text/plain request bodies, allowing an attacker who lures an authenticated user to a                   malicious site to perform actions on the user's behalf through REST and WebSocket endpoints. This issue affects Apache Zeppelin versions 0.6.0 through 0.12.0. Users are recommended to upgrade to version 0.12.1, which fixes this issue.

CVE-2026-28814HIGH 7.5

Arbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows attacker to obtain sensitive data stored in JSPWiki variables. Users are recommended to upgrade to version 2.12.4 or 3.0.0, which fixes this issue.

CVE-2026-28813HIGH 8.8

Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking, which leads to csrf vulnerabilities. Users are recommended to upgrade to version 2.12.4, which fixes this issue.

CVE-2026-28812CRITICAL 9.8

UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate privileges. Users are recommended to upgrade to version 2.12.4 or newer which fixes this issue.

CVE-2026-28811HIGH 7.5

Debug Messages Revealing Unnecessary Information in Apache JSPWiki up to 2.12.3. Users are recommended to upgrade to version 2.12.4, which fixes this issue.

CVE-2026-23985MEDIUM 6.5

A Regular Expression Denial of Service (ReDoS) vulnerability exists in Apache Superset versions 1.5.0 through 5.0.0. The vulnerability is located in the sql_parse.py component, specifically within the SQL_REGEX used for parsing SQL statements in the sqlparse library integration. The affected regular expression contains overlapping disjunctions that share a common outer quantifier. An authenticated attacker can exploit this by sending a maliciously crafted input string (specifically a long sequence of backslashes or similar characters) to endpoints that process SQL queries This issue affects Apache Superset: before 6.0.0. Users are recommended to upgrade to version 6.0.0, which fixes the issue.  Workarounds: ● WAF Rules: Implement Web Application Firewall (WAF) rules to detect and block requests containing excessively long sequences of backslashes or suspicious repeated patterns in the queries.extras.where parameter. ● Rate Limiting: Ensure strict rate limiting is applied to the /api/v1/chart/data endpoint to reduce the impact of potential attacks.

CVE-2026-23981MEDIUM 4.3

An Improper Authorization vulnerability exists in Apache Superset allowing an authenticated user with permissions to update charts to modify dashboards they do not own. When updating a chart's properties via the REST API, a user can provide a list of dashboard IDs (dashboards) to associate the chart with. The validation logic in the UpdateChartCommand failed to verify that the user had write permissions for the target dashboards specified in the request body. This issue affects Apache Superset: before 6.0.0. Users are recommended to upgrade to version 6.0.0, which fixes the issue.

CVE-2026-58187LOW 3.7

The Apache Traffic Server multiplexer plugin overruns its chunk-decode buffer on upstream input, enabling denial of service. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58186HIGH 7.5

The Apache Traffic Server webp_transform plugin can decode unsafely and serve mislabeled, cacheable responses. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58185MEDIUM 5.9

The Apache Traffic Server intercept plugin has a use-after-free. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58184HIGH 8.2

The Apache Traffic Server header_rewrite plugin can crash or corrupt memory during cookie operations and CIDR condition matching. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58183MEDIUM 5.9

The Apache Traffic Server prefetch plugin can crash when processing attacker-influenced input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58182HIGH 8.6

The Apache Traffic Server ts_lua plugin mishandles initialization, transform context, and per-instance state. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58181HIGH 7.5

The Apache Traffic Server uri_signing and url_sig plugins can exhaust the stack or crash on attacker input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58180HIGH 7.5

The Apache Traffic Server txn_box plugin overflows the stack from attacker-controlled input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58179HIGH 8.1

The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58178HIGH 7.5

The Apache Traffic Server ESI plugin can recurse without bound and fetch attacker-controlled URLs. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58177HIGH 8.1

The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 10.1.4, which fix the issue.