{"schema_version":1,"title":"Apache Software Foundation vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 196 vulnerabilities in Apache Software Foundation: 0 in the last 7 days and 86 in the last 90 days, 23 of them critical and 1 exploited in the wild. The most recent, CVE-2026-64607, was published on 31 July 2026. 21 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/apache-software-foundation","json_url":"https://junglewise.ai/threats/vendors/apache-software-foundation.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/apache-software-foundation","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":45,"all_time":196,"critical":23,"exploited":1,"last_7_days":0,"last_30_days":0,"last_90_days":86,"last_365_days":182},"latest":[{"cve":"CVE-2026-64607","cvss":5.3,"epss":0.0063,"slug":"cve-2026-64607-apache-httpcomponents-client-resource-leak-in-classic-i-o-model","title":"Apache HttpComponents Client resource leak in classic I/O model","severity":"medium","exploited":false,"published_at":"2026-07-31T11:17:11.71+00:00","url":"https://junglewise.ai/threats/cve-2026-64607-apache-httpcomponents-client-resource-leak-in-classic-i-o-model"},{"cve":"CVE-2026-62391","cvss":0,"slug":"cve-2026-62391-apache-kyuubi-path-traversal-via-spark-config-alias-bypass","title":"Apache Kyuubi path traversal via Spark config alias bypass","severity":"info","exploited":false,"published_at":"2026-07-31T11:17:11.593+00:00","url":"https://junglewise.ai/threats/cve-2026-62391-apache-kyuubi-path-traversal-via-spark-config-alias-bypass"},{"cve":"CVE-2026-44615","cvss":0,"slug":"cve-2026-44615-apache-zeppelin-path-traversal-in-filesystemnotebookrepo","title":"Apache Zeppelin path traversal in FileSystemNotebookRepo","severity":"info","exploited":false,"published_at":"2026-07-31T11:17:10.087+00:00","url":"https://junglewise.ai/threats/cve-2026-44615-apache-zeppelin-path-traversal-in-filesystemnotebookrepo"},{"cve":"CVE-2026-66756","cvss":6.9,"slug":"cve-2026-66756-apache-tika-path-protection-bypass-in-tika-server-unpack-endpoint","title":"Apache Tika path protection bypass in tika-server unpack endpoint","severity":"info","exploited":false,"published_at":"2026-07-30T20:18:13.877+00:00","url":"https://junglewise.ai/threats/cve-2026-66756-apache-tika-path-protection-bypass-in-tika-server-unpack-endpoint"},{"cve":"CVE-2026-66755","cvss":5.9,"slug":"cve-2026-66755-apache-tika-path-traversal-in-isa-tab-parser","title":"Apache Tika path traversal in ISA-Tab parser","severity":"info","exploited":false,"published_at":"2026-07-30T20:18:13.717+00:00","url":"https://junglewise.ai/threats/cve-2026-66755-apache-tika-path-traversal-in-isa-tab-parser"},{"cve":"CVE-2026-52680","cvss":0,"slug":"cve-2026-52680-apache-kyuubi-path-traversal-in-rest-batch-multipart-upload","title":"Apache Kyuubi path traversal in REST batch multipart upload","severity":"info","exploited":false,"published_at":"2026-07-30T16:17:14.04+00:00","url":"https://junglewise.ai/threats/cve-2026-52680-apache-kyuubi-path-traversal-in-rest-batch-multipart-upload"},{"cve":"CVE-2026-48910","cvss":6.5,"slug":"cve-2026-48910-apache-jspwiki-xss-in-markdown-renderer-error-processing","title":"Apache JSPWiki XSS in markdown renderer error processing","severity":"medium","exploited":false,"published_at":"2026-07-30T16:17:12.637+00:00","url":"https://junglewise.ai/threats/cve-2026-48910-apache-jspwiki-xss-in-markdown-renderer-error-processing"},{"cve":"CVE-2026-44617","cvss":0,"slug":"cve-2026-44617-apache-zeppelin-ldap-filter-injection-in-ldaprealm","title":"Apache Zeppelin LDAP filter injection in LdapRealm","severity":"info","exploited":false,"published_at":"2026-07-30T16:17:12.373+00:00","url":"https://junglewise.ai/threats/cve-2026-44617-apache-zeppelin-ldap-filter-injection-in-ldaprealm"},{"cve":"CVE-2026-44616","cvss":0,"slug":"cve-2026-44616-apache-zeppelin-ldap-injection-in-activedirectorygrouprealm","title":"Apache Zeppelin LDAP injection in ActiveDirectoryGroupRealm","severity":"info","exploited":false,"published_at":"2026-07-30T16:17:12.257+00:00","url":"https://junglewise.ai/threats/cve-2026-44616-apache-zeppelin-ldap-injection-in-activedirectorygrouprealm"},{"cve":"CVE-2026-44613","cvss":0,"slug":"cve-2026-44613-apache-zeppelin-csrf-in-rest-and-websocket-endpoints","title":"Apache Zeppelin CSRF in REST and WebSocket endpoints","severity":"info","exploited":false,"published_at":"2026-07-30T16:17:12.13+00:00","url":"https://junglewise.ai/threats/cve-2026-44613-apache-zeppelin-csrf-in-rest-and-websocket-endpoints"},{"cve":"CVE-2026-28814","cvss":0,"slug":"cve-2026-28814-apache-jspwiki-unauthenticated-wiki-markup-rendering","title":"Apache JSPWiki unauthenticated wiki markup rendering","severity":"info","exploited":false,"published_at":"2026-07-30T16:17:11.183+00:00","url":"https://junglewise.ai/threats/cve-2026-28814-apache-jspwiki-unauthenticated-wiki-markup-rendering"},{"cve":"CVE-2026-28813","cvss":0,"slug":"cve-2026-28813-apache-jspwiki-json-hijacking-leading-to-csrf","title":"Apache JSPWiki JSON hijacking leading to CSRF","severity":"info","exploited":false,"published_at":"2026-07-30T16:17:11.07+00:00","url":"https://junglewise.ai/threats/cve-2026-28813-apache-jspwiki-json-hijacking-leading-to-csrf"},{"cve":"CVE-2026-28812","cvss":0,"slug":"cve-2026-28812-apache-jspwiki-privilege-escalation-in-usermanager","title":"Apache JSPWiki privilege escalation in UserManager","severity":"info","exploited":false,"published_at":"2026-07-30T16:17:10.967+00:00","url":"https://junglewise.ai/threats/cve-2026-28812-apache-jspwiki-privilege-escalation-in-usermanager"},{"cve":"CVE-2026-28811","cvss":3.7,"slug":"cve-2026-28811-apache-jspwiki-information-disclosure-in-debug-messages","title":"Apache JSPWiki information disclosure in debug messages","severity":"info","exploited":false,"published_at":"2026-07-30T16:17:10.85+00:00","url":"https://junglewise.ai/threats/cve-2026-28811-apache-jspwiki-information-disclosure-in-debug-messages"},{"cve":"CVE-2026-59243","cvss":8.1,"slug":"cve-2026-59243-apache-airflow-fab-provider-authentication-bypass-in-azure-ad","title":"Apache Airflow FAB provider authentication bypass in Azure AD OAuth","severity":"info","exploited":false,"published_at":"2026-07-29T10:16:44.39+00:00","url":"https://junglewise.ai/threats/cve-2026-59243-apache-airflow-fab-provider-authentication-bypass-in-azure-ad"},{"cve":"CVE-2026-23904","slug":"cve-2026-23904-apache-kyuubi-ssrf-in-engine-ui-proxy","title":"Apache Kyuubi SSRF in Engine UI proxy","severity":"info","exploited":false,"published_at":"2026-07-29T10:16:40.913+00:00","url":"https://junglewise.ai/threats/cve-2026-23904-apache-kyuubi-ssrf-in-engine-ui-proxy"},{"cve":"CVE-2026-66713","cvss":9.8,"slug":"cve-2026-66713-apache-axis2-java-remote-code-execution-in-tribes-clustering","title":"Apache Axis2/Java remote code execution in Tribes clustering component","severity":"info","exploited":false,"published_at":"2026-07-28T15:17:50.43+00:00","url":"https://junglewise.ai/threats/cve-2026-66713-apache-axis2-java-remote-code-execution-in-tribes-clustering"},{"cve":"CVE-2026-66391","slug":"cve-2026-66391-apache-wicket-protection-mechanism-failure-via-weak-randomness","title":"Apache Wicket protection mechanism failure via weak randomness","severity":"info","exploited":false,"published_at":"2026-07-27T17:16:41.75+00:00","url":"https://junglewise.ai/threats/cve-2026-66391-apache-wicket-protection-mechanism-failure-via-weak-randomness"},{"cve":"CVE-2026-66053","cvss":5.9,"epss":0.0029,"slug":"cve-2026-66053-apache-thrift-certificate-validation-bypass-in-python-bindings","title":"Apache Thrift certificate validation bypass in Python bindings","severity":"medium","exploited":false,"published_at":"2026-07-27T12:16:55.027+00:00","url":"https://junglewise.ai/threats/cve-2026-66053-apache-thrift-certificate-validation-bypass-in-python-bindings"},{"cve":"CVE-2026-55969","cvss":8.7,"slug":"cve-2026-55969-apache-thrift-integer-overflow-in-tprotocol","title":"Apache Thrift integer overflow in TProtocol checkReadBytesAvailable","severity":"info","exploited":false,"published_at":"2026-07-27T12:16:45.823+00:00","url":"https://junglewise.ai/threats/cve-2026-55969-apache-thrift-integer-overflow-in-tprotocol"},{"cve":"CVE-2026-49158","cvss":7.5,"slug":"cve-2026-49158-apache-thrift-ruby-bindings-data-amplification-in","title":"Apache Thrift Ruby bindings data amplification in THeaderTransport","severity":"high","exploited":false,"published_at":"2026-07-27T12:16:45.113+00:00","url":"https://junglewise.ai/threats/cve-2026-49158-apache-thrift-ruby-bindings-data-amplification-in"},{"cve":"CVE-2026-49326","cvss":0,"slug":"cve-2026-49326-apache-hbase-missing-authorization-in-thrift-and-rest-services","title":"Apache HBase missing authorization in Thrift and REST services","severity":"info","exploited":false,"published_at":"2026-07-24T15:17:31.163+00:00","url":"https://junglewise.ai/threats/cve-2026-49326-apache-hbase-missing-authorization-in-thrift-and-rest-services"},{"cve":"CVE-2026-66144","cvss":0,"slug":"cve-2026-66144-apache-neethi-denial-of-service-in-remote-policy-retrieval","title":"Apache Neethi denial of service in remote policy retrieval","severity":"info","exploited":false,"published_at":"2026-07-24T13:18:29.467+00:00","url":"https://junglewise.ai/threats/cve-2026-66144-apache-neethi-denial-of-service-in-remote-policy-retrieval"},{"cve":"CVE-2026-66143","cvss":0,"slug":"cve-2026-66143-apache-neethi-denial-of-service-via-policy-normalization-bypass","title":"Apache Neethi denial of service via policy normalization bypass","severity":"info","exploited":false,"published_at":"2026-07-24T13:18:29.35+00:00","url":"https://junglewise.ai/threats/cve-2026-66143-apache-neethi-denial-of-service-via-policy-normalization-bypass"},{"cve":"CVE-2026-66142","cvss":7.5,"slug":"cve-2026-66142-apache-neethi-denial-of-service-via-uncontrolled-recursion-in","title":"Apache Neethi denial of service via uncontrolled recursion in policy parsing","severity":"info","exploited":false,"published_at":"2026-07-24T13:18:29.237+00:00","url":"https://junglewise.ai/threats/cve-2026-66142-apache-neethi-denial-of-service-via-uncontrolled-recursion-in"}],"vendor":{"hub":true,"name":"Apache Software Foundation","slug":"apache-software-foundation","description":"Non-profit organization that supports open-source software development projects.","url":"https://junglewise.ai/threats/vendors/apache-software-foundation"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":10},{"week":"2026-07-06","critical":4,"exploited":0,"vulnerabilities":28},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":11},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":16},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":21},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2026-34486","cvss":7.5,"epss":0.0656,"slug":"cve-2026-34486-apache-tomcat-encryption-bypass-in-encryptinterceptor","title":"Apache Tomcat encryption bypass in EncryptInterceptor","severity":"critical","exploited":true,"published_at":"2026-04-09T20:16:25.063+00:00","url":"https://junglewise.ai/threats/cve-2026-34486-apache-tomcat-encryption-bypass-in-encryptinterceptor"},{"cve":"CVE-2019-0219","cvss":9.8,"epss":0.0783,"slug":"cve-2019-0219-apache-cordova-plugin-inappbrowser-privilege-escalation-on-android","title":"Apache cordova-plugin-inappbrowser privilege escalation on Android","severity":"critical","exploited":false,"published_at":"2020-09-04T17:57:43+00:00","url":"https://junglewise.ai/threats/cve-2019-0219-apache-cordova-plugin-inappbrowser-privilege-escalation-on-android"},{"cve":"CVE-2023-25693","cvss":9.8,"epss":0.019,"slug":"cve-2023-25693-apache-airflow-sqoop-provider-improper-input-validation","title":"Apache Airflow Sqoop Provider improper input validation","severity":"critical","exploited":false,"published_at":"2023-02-24T12:31:20+00:00","url":"https://junglewise.ai/threats/cve-2023-25693-apache-airflow-sqoop-provider-improper-input-validation"},{"cve":"CVE-2026-47323","cvss":9.8,"epss":0.0161,"slug":"cve-2026-47323-apache-camel-header-injection-in-cxf-and-knative-components","title":"Apache Camel header injection in CXF and Knative components","severity":"critical","exploited":false,"published_at":"2026-05-19T14:16:48.653+00:00","url":"https://junglewise.ai/threats/cve-2026-47323-apache-camel-header-injection-in-cxf-and-knative-components"},{"cve":"CVE-2022-46337","cvss":9.8,"epss":0.0142,"slug":"cve-2022-46337-apache-derby-ldap-injection-in-authenticator","title":"Apache Derby LDAP injection in authenticator","severity":"critical","exploited":false,"published_at":"2023-11-20T09:30:31+00:00","url":"https://junglewise.ai/threats/cve-2022-46337-apache-derby-ldap-injection-in-authenticator"},{"cve":"CVE-2026-50633","cvss":9.8,"epss":0.0127,"slug":"cve-2026-50633-apache-cxf-jndi-injection-in-jca-integration-module","title":"Apache CXF JNDI injection in JCA integration module","severity":"critical","exploited":false,"published_at":"2026-06-12T10:16:23.297+00:00","url":"https://junglewise.ai/threats/cve-2026-50633-apache-cxf-jndi-injection-in-jca-integration-module"},{"cve":"CVE-2026-53913","cvss":9.8,"epss":0.0109,"slug":"cve-2026-53913-apache-camel-keycloak-authentication-bypass-in","title":"Apache Camel Keycloak authentication bypass in KeycloakSecurityPolicy","severity":"critical","exploited":false,"published_at":"2026-07-06T09:16:38.753+00:00","url":"https://junglewise.ai/threats/cve-2026-53913-apache-camel-keycloak-authentication-bypass-in"},{"cve":"CVE-2026-50628","cvss":9.8,"epss":0.0102,"slug":"cve-2026-50628-apache-cxf-inverted-ip-binding-check-in-oauthrequestfilter","title":"Apache CXF inverted IP binding check in OAuthRequestFilter","severity":"critical","exploited":false,"published_at":"2026-06-12T10:16:22.71+00:00","url":"https://junglewise.ai/threats/cve-2026-50628-apache-cxf-inverted-ip-binding-check-in-oauthrequestfilter"},{"cve":"CVE-2025-67895","cvss":9.8,"epss":0.01,"slug":"cve-2025-67895-apache-airflow-providers-edge3-rce-in-web-server-context","title":"Apache Airflow Providers Edge3 RCE in web server context","severity":"critical","exploited":false,"published_at":"2025-12-17T12:30:12+00:00","url":"https://junglewise.ai/threats/cve-2025-67895-apache-airflow-providers-edge3-rce-in-web-server-context"},{"cve":"CVE-2026-48207","cvss":9.8,"epss":0.0082,"slug":"cve-2026-48207-apache-fory-pyfory-deserialization-bypass-in-reduceserializer","title":"Apache Fory PyFory deserialization bypass in ReduceSerializer","severity":"critical","exploited":false,"published_at":"2026-05-21T17:16:21.857+00:00","url":"https://junglewise.ai/threats/cve-2026-48207-apache-fory-pyfory-deserialization-bypass-in-reduceserializer"}],"generated_at":"2026-09-26T14:07:00.158513+00:00","technologies":[{"name":"Apache Software Foundation IoTDB","slug":"iotdb","vulnerabilities":13,"url":"https://junglewise.ai/threats/technologies/iotdb"},{"name":"Apache Software Foundation Apache CXF","slug":"cxf","vulnerabilities":10,"url":"https://junglewise.ai/threats/technologies/cxf"},{"name":"Apache Software Foundation ActiveMQ All","slug":"activemq-all","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/activemq-all"},{"name":"Apache Software Foundation Answer","slug":"answer","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/answer"},{"name":"Apache Software Foundation Dolphinscheduler","slug":"dolphinscheduler","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/dolphinscheduler"},{"name":"Apache Software Foundation NimBLE","slug":"nimble","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/nimble"},{"name":"Apache Software Foundation JSPWiki","slug":"jspwiki","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/jspwiki"},{"name":"Apache Software Foundation Apache Kvrocks","slug":"kvrocks","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/kvrocks"},{"name":"Apache Software Foundation NiFi","slug":"nifi","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/nifi"},{"name":"Apache Software Foundation Apache Wicket","slug":"wicket","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/wicket"},{"name":"Apache Software Foundation Gravitino","slug":"gravitino","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/gravitino"},{"name":"Apache Software Foundation Syncope","slug":"syncope","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/syncope"},{"name":"Apache Software Foundation Zeppelin","slug":"zeppelin","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/zeppelin"},{"name":"Apache Software Foundation ActiveMQ Client","slug":"activemq-client","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/activemq-client"},{"name":"Apache Software Foundation Airflow FAB Provider","slug":"airflow-fab-provider","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/airflow-fab-provider"},{"name":"Apache Software Foundation Fineract","slug":"fineract","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/fineract"},{"name":"Apache Software Foundation Fury","slug":"fury","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/fury"},{"name":"Apache Software Foundation Kyuubi","slug":"kyuubi","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/kyuubi"},{"name":"Apache Software Foundation Log4j Core","slug":"log4j-core","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/log4j-core"},{"name":"Apache Software Foundation Apache Neethi","slug":"neethi","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/neethi"},{"name":"Apache Software Foundation OpenMeetings","slug":"openmeetings","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/openmeetings"}]}