Vendor
Eclipse vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 24 vulnerabilities in Eclipse: 1 in the last 7 days and 19 in the last 90 days, 5 of them critical and 1 exploited in the wild. The most recent, CVE-2026-92612, was published on 21 September 2026. 1 technology has a page of its own.
- Last 7 days
- 1
- Last 90 days
- 19
- Critical, all time
- 5
- Exploited in the wild
- 1
About Eclipse
A non-profit foundation that manages the Eclipse ecosystem, including the Eclipse IDE and various open-source projects.
Eclipse technologies
Latest Eclipse vulnerabilities
- CVE-2026-92612: Eclipse iceoryx2 unsafe string handling in StaticStringinfoEPSS 0.1%
- CVE-2026-92611: Eclipse Ankaios authorization bypass in log access controlinfoEPSS 0.3%
- CVE-2026-86836: Eclipse Ankaios agent FIFO hijacking via predictable pathinfoEPSS 0.1%
- CVE-2026-88819: Eclipse Data Plane Core proof-of-possession bypass in JWT refreshinfoEPSS 0.2%
- CVE-2026-78299: Eclipse Embedded CDT path traversal in CMSIS-Pack extractioncriticalCVSS 9.1EPSS 0.5%
- CVE-2026-86464: Eclipse aeriOS Identity Manager insecure default credentials and exposureinfoCVSS 0EPSS 0.5%
- CVE-2026-86590: Eclipse Che dashboard SSRF in data resolver endpointinfoCVSS 0EPSS 0.4%
- CVE-2026-85201: Eclipse Ankaios agent unbounded memory allocation in Control InterfaceinfoEPSS 0.2%
- CVE-2026-84173: Eclipse Ankaios authorization bypass via multi-segment wildcard rulesinfoEPSS 0.2%
- CVE-2026-84736: Eclipse aeriOS Federator TLS certificate validation disabled by defaultinfoCVSS 7.4EPSS 0.3%
- CVE-2026-85199: Eclipse aeriOS Self-orchestrator path traversal in REST APIinfoCVSS 8.6EPSS 0.9%
- CVE-2026-82180: Eclipse Arrowhead CertificateMqttFilter certificate validation bypassinfoCVSS 7.5EPSS 0.3%
- CVE-2026-80515: Eclipse Arrowhead management authorization bypass via percent-encoded pathsinfoCVSS 9.1EPSS 0.5%
- CVE-2026-82955: Eclipse aeriOS KrakenD insecure JWKS retrieval due to disabled TLS verificationinfoCVSS 7.4EPSS 0.2%
- CVE-2026-82958: Eclipse Ditto ImplicitThingCreationMessageMapper JSON injectioninfoCVSS 8.2EPSS 0.4%
- CVE-2026-84175: Eclipse Ditto server-side request forgery in WoT ThingModel fetchinfoCVSS 6.5EPSS 0.4%
- CVE-2026-18918: Eclipse Lyo OAuth authorization bypass in 2-legged flowsinfoEPSS 0.4%
- CVE-2026-79653: Eclipse SW360 arbitrary file path traversal in attachment storageinfoCVSS 0EPSS 0.5%
- CVE-2026-15803: Eclipse RDF4J XML External Entity processing in XML parserinfoCVSS 6.5EPSS 0.5%
- CVE-2026-6918: Eclipse OpenJ9 OOB read and crash in JITServerhighCVSS 7.5EPSS 0.4%
- CVE-2026-24457: Eclipse OpenMQ arbitrary file read via unsafe configuration parsingcriticalCVSS 9.1EPSS 0.6%
- CVE-2025-12548: Eclipse Che che-machine-exec unauthenticated remote code executioncriticalCVSS 9EPSS 1.3%
- CVE-2025-67109: Eclipse Cyclone DDS certificate expiration bypass in authentication plugincriticalCVSS 10EPSS 0.3%
- CVE-2023-44487: HTTP/2 Rapid Reset Attack Vulnerabilitycriticalexploited in the wildCVSS 7.5
Most severe Eclipse vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2023-44487: HTTP/2 Rapid Reset Attack Vulnerabilitycriticalexploited in the wildCVSS 7.5
- CVE-2025-67109: Eclipse Cyclone DDS certificate expiration bypass in authentication plugincriticalCVSS 10EPSS 0.3%
- CVE-2026-24457: Eclipse OpenMQ arbitrary file read via unsafe configuration parsingcriticalCVSS 9.1EPSS 0.6%
- CVE-2026-78299: Eclipse Embedded CDT path traversal in CMSIS-Pack extractioncriticalCVSS 9.1EPSS 0.5%
- CVE-2025-12548: Eclipse Che che-machine-exec unauthenticated remote code executioncriticalCVSS 9EPSS 1.3%
- CVE-2026-6918: Eclipse OpenJ9 OOB read and crash in JITServerhighCVSS 7.5EPSS 0.4%
- CVE-2026-80515: Eclipse Arrowhead management authorization bypass via percent-encoded pathsinfoCVSS 9.1EPSS 0.5%
- CVE-2026-85199: Eclipse aeriOS Self-orchestrator path traversal in REST APIinfoCVSS 8.6EPSS 0.9%
- CVE-2026-82958: Eclipse Ditto ImplicitThingCreationMessageMapper JSON injectioninfoCVSS 8.2EPSS 0.4%
- CVE-2026-82180: Eclipse Arrowhead CertificateMqttFilter certificate validation bypassinfoCVSS 7.5EPSS 0.3%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 1 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 2 | 0 | |
| 31 Aug 2026 | 7 | 0 | |
| 7 Sep 2026 | 4 | 0 | |
| 14 Sep 2026 | 4 | 1 | |
| 21 Sep 2026 | 1 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/eclipse.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Eclipse vulnerabilities", https://junglewise.ai/threats/vendors/eclipse, 26 September 2026.