{"schema_version":1,"title":"Red Hat Fuse 7 vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 4 vulnerabilities in Red Hat Fuse 7: 0 in the last 7 days and 0 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-40477, was published on 17 April 2026.","url":"https://junglewise.ai/threats/technologies/fuse-7","json_url":"https://junglewise.ai/threats/technologies/fuse-7.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/fuse-7","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":3,"all_time":4,"critical":1,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":4},"latest":[{"cve":"CVE-2026-40477","cvss":9,"epss":0.0094,"slug":"cve-2026-40477-thymeleaf-security-bypass-in-expression-execution-mechanisms","title":"Thymeleaf security bypass in expression execution mechanisms","severity":"critical","exploited":false,"published_at":"2026-04-17T22:16:33.5+00:00","url":"https://junglewise.ai/threats/cve-2026-40477-thymeleaf-security-bypass-in-expression-execution-mechanisms"},{"cve":"CVE-2026-2818","cvss":8.2,"epss":0.0025,"slug":"cve-2026-2818-vmware-spring-data-geode-path-traversal-in-snapshot-import","title":"VMware Spring Data Geode Path Traversal in Snapshot Import","severity":"high","exploited":false,"published_at":"2026-02-20T17:25:57.98+00:00","url":"https://junglewise.ai/threats/cve-2026-2818-vmware-spring-data-geode-path-traversal-in-snapshot-import"},{"cve":"CVE-2024-4027","cvss":7.5,"epss":0.0036,"slug":"cve-2024-4027-red-hat-undertow-denial-of-service-via-outofmemoryerror-in","title":"Red Hat Undertow denial of service via OutOfMemoryError in getParameterNames","severity":"high","exploited":false,"published_at":"2026-01-30T15:16:07.113+00:00","url":"https://junglewise.ai/threats/cve-2024-4027-red-hat-undertow-denial-of-service-via-outofmemoryerror-in"},{"cve":"CVE-2026-0603","cvss":8.3,"epss":0.0087,"slug":"cve-2026-0603-hibernate-orm-second-order-sql-injection-in","title":"Hibernate ORM second-order SQL injection in InlineIdsOrClauseBuilder","severity":"high","exploited":false,"published_at":"2026-01-23T07:15:53.66+00:00","url":"https://junglewise.ai/threats/cve-2026-0603-hibernate-orm-second-order-sql-injection-in"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Red Hat Enterprise Linux 9","slug":"enterprise-linux-9","vulnerabilities":146,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-9"},{"name":"Red Hat Enterprise Linux 10","slug":"enterprise-linux-10","vulnerabilities":140,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-10"},{"name":"Red Hat Enterprise Linux 8","slug":"enterprise-linux-8","vulnerabilities":132,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-8"},{"name":"Red Hat Enterprise Linux 7","slug":"enterprise-linux-7","vulnerabilities":67,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-7"},{"name":"Red Hat Enterprise Linux 6","slug":"enterprise-linux-6","vulnerabilities":55,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-6"},{"name":"Red Hat Build of Keycloak","slug":"red-hat-build-of-keycloak","vulnerabilities":54,"url":"https://junglewise.ai/threats/technologies/red-hat-build-of-keycloak"},{"name":"Red Hat Keycloak","slug":"build-of-keycloak","vulnerabilities":48,"url":"https://junglewise.ai/threats/technologies/build-of-keycloak"},{"name":"Red Hat Enterprise Linux AppStream","slug":"enterprise-linux-appstream","vulnerabilities":46,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-appstream"},{"name":"Red Hat OpenShift Container Platform 4","slug":"openshift-container-platform-4","vulnerabilities":36,"url":"https://junglewise.ai/threats/technologies/openshift-container-platform-4"},{"name":"Red Hat Developer Hub","slug":"developer-hub","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/developer-hub"},{"name":"Red Hat Multicluster Global Hub","slug":"multicluster-global-hub","vulnerabilities":19,"url":"https://junglewise.ai/threats/technologies/multicluster-global-hub"},{"name":"Red Hat AI Inference Server","slug":"ai-inference-server","vulnerabilities":16,"url":"https://junglewise.ai/threats/technologies/ai-inference-server"}],"technology":{"hub":true,"name":"Red Hat Fuse 7","slug":"fuse-7","vendor":{"name":"Red Hat","slug":"red-hat","url":"https://junglewise.ai/threats/vendors/red-hat"},"aliases":[],"category":"middleware","homepage":"https://access.redhat.com/products/red-hat-fuse","description":"Red Hat Fuse 7 is a distributed, cloud-native integration platform for connecting applications and services.","url":"https://junglewise.ai/threats/technologies/fuse-7"},"most_severe":[{"cve":"CVE-2026-40477","cvss":9,"epss":0.0094,"slug":"cve-2026-40477-thymeleaf-security-bypass-in-expression-execution-mechanisms","title":"Thymeleaf security bypass in expression execution mechanisms","severity":"critical","exploited":false,"published_at":"2026-04-17T22:16:33.5+00:00","url":"https://junglewise.ai/threats/cve-2026-40477-thymeleaf-security-bypass-in-expression-execution-mechanisms"},{"cve":"CVE-2026-0603","cvss":8.3,"epss":0.0087,"slug":"cve-2026-0603-hibernate-orm-second-order-sql-injection-in","title":"Hibernate ORM second-order SQL injection in InlineIdsOrClauseBuilder","severity":"high","exploited":false,"published_at":"2026-01-23T07:15:53.66+00:00","url":"https://junglewise.ai/threats/cve-2026-0603-hibernate-orm-second-order-sql-injection-in"},{"cve":"CVE-2026-2818","cvss":8.2,"epss":0.0025,"slug":"cve-2026-2818-vmware-spring-data-geode-path-traversal-in-snapshot-import","title":"VMware Spring Data Geode Path Traversal in Snapshot Import","severity":"high","exploited":false,"published_at":"2026-02-20T17:25:57.98+00:00","url":"https://junglewise.ai/threats/cve-2026-2818-vmware-spring-data-geode-path-traversal-in-snapshot-import"},{"cve":"CVE-2024-4027","cvss":7.5,"epss":0.0036,"slug":"cve-2024-4027-red-hat-undertow-denial-of-service-via-outofmemoryerror-in","title":"Red Hat Undertow denial of service via OutOfMemoryError in getParameterNames","severity":"high","exploited":false,"published_at":"2026-01-30T15:16:07.113+00:00","url":"https://junglewise.ai/threats/cve-2024-4027-red-hat-undertow-denial-of-service-via-outofmemoryerror-in"}],"generated_at":"2026-09-26T14:07:00.158513+00:00"}