{"schema_version":1,"title":"Eclipse vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 24 vulnerabilities in Eclipse: 1 in the last 7 days and 19 in the last 90 days, 5 of them critical and 1 exploited in the wild. The most recent, CVE-2026-92612, was published on 21 September 2026. 1 technology has a page of its own.","url":"https://junglewise.ai/threats/vendors/eclipse","json_url":"https://junglewise.ai/threats/vendors/eclipse.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/eclipse","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":1,"all_time":24,"critical":5,"exploited":1,"last_7_days":1,"last_30_days":17,"last_90_days":19,"last_365_days":23},"latest":[{"cve":"CVE-2026-92612","epss":0.0015,"slug":"cve-2026-92612-in-eclipse-iceoryx2-versions-greater-than-v0-8-0-the-staticstring","title":"Eclipse iceoryx2 unsafe string handling in StaticString","severity":"info","exploited":false,"published_at":"2026-09-21T11:17:12.59+00:00","url":"https://junglewise.ai/threats/cve-2026-92612-in-eclipse-iceoryx2-versions-greater-than-v0-8-0-the-staticstring"},{"cve":"CVE-2026-92611","epss":0.003,"slug":"cve-2026-92611-eclipse-ankaios-authorization-bypass-in-log-access-control","title":"Eclipse Ankaios authorization bypass in log access control","severity":"info","exploited":false,"published_at":"2026-09-17T11:17:03.21+00:00","url":"https://junglewise.ai/threats/cve-2026-92611-eclipse-ankaios-authorization-bypass-in-log-access-control"},{"cve":"CVE-2026-86836","epss":0.0011,"slug":"cve-2026-86836-eclipse-ankaios-agent-fifo-hijacking-via-predictable-path","title":"Eclipse Ankaios agent FIFO hijacking via predictable path","severity":"info","exploited":false,"published_at":"2026-09-14T18:20:20.193+00:00","url":"https://junglewise.ai/threats/cve-2026-86836-eclipse-ankaios-agent-fifo-hijacking-via-predictable-path"},{"cve":"CVE-2026-88819","epss":0.0017,"slug":"cve-2026-88819-eclipse-data-plane-core-proof-of-possession-bypass-in-jwt-refresh","title":"Eclipse Data Plane Core proof-of-possession bypass in JWT refresh","severity":"info","exploited":false,"published_at":"2026-09-14T16:17:22.24+00:00","url":"https://junglewise.ai/threats/cve-2026-88819-eclipse-data-plane-core-proof-of-possession-bypass-in-jwt-refresh"},{"cve":"CVE-2026-78299","cvss":9.1,"epss":0.0054,"slug":"cve-2026-78299-eclipse-embedded-cdt-path-traversal-in-cmsis-pack-extraction","title":"Eclipse Embedded CDT path traversal in CMSIS-Pack extraction","severity":"critical","exploited":false,"published_at":"2026-09-14T13:18:46.87+00:00","url":"https://junglewise.ai/threats/cve-2026-78299-eclipse-embedded-cdt-path-traversal-in-cmsis-pack-extraction"},{"cve":"CVE-2026-86464","cvss":0,"epss":0.0055,"slug":"cve-2026-86464-eclipse-aerios-identity-manager-insecure-default-credentials-and","title":"Eclipse aeriOS Identity Manager insecure default credentials and exposure","severity":"info","exploited":false,"published_at":"2026-09-08T20:18:52.96+00:00","url":"https://junglewise.ai/threats/cve-2026-86464-eclipse-aerios-identity-manager-insecure-default-credentials-and"},{"cve":"CVE-2026-86590","cvss":0,"epss":0.0039,"slug":"cve-2026-86590-eclipse-che-dashboard-ssrf-in-data-resolver-endpoint","title":"Eclipse Che dashboard SSRF in data resolver endpoint","severity":"info","exploited":false,"published_at":"2026-09-08T10:17:14.197+00:00","url":"https://junglewise.ai/threats/cve-2026-86590-eclipse-che-dashboard-ssrf-in-data-resolver-endpoint"},{"cve":"CVE-2026-85201","epss":0.0016,"slug":"cve-2026-85201-eclipse-ankaios-agent-unbounded-memory-allocation-in-control","title":"Eclipse Ankaios agent unbounded memory allocation in Control Interface","severity":"info","exploited":false,"published_at":"2026-09-07T11:17:37.49+00:00","url":"https://junglewise.ai/threats/cve-2026-85201-eclipse-ankaios-agent-unbounded-memory-allocation-in-control"},{"cve":"CVE-2026-84173","epss":0.0016,"slug":"cve-2026-84173-eclipse-ankaios-authorization-bypass-via-multi-segment-wildcard","title":"Eclipse Ankaios authorization bypass via multi-segment wildcard rules","severity":"info","exploited":false,"published_at":"2026-09-07T10:16:54.823+00:00","url":"https://junglewise.ai/threats/cve-2026-84173-eclipse-ankaios-authorization-bypass-via-multi-segment-wildcard"},{"cve":"CVE-2026-84736","cvss":7.4,"epss":0.0027,"slug":"cve-2026-84736-eclipse-aerios-federator-tls-certificate-validation-disabled-by","title":"Eclipse aeriOS Federator TLS certificate validation disabled by default","severity":"info","exploited":false,"published_at":"2026-09-03T17:17:25.427+00:00","url":"https://junglewise.ai/threats/cve-2026-84736-eclipse-aerios-federator-tls-certificate-validation-disabled-by"},{"cve":"CVE-2026-85199","cvss":8.6,"epss":0.0091,"slug":"cve-2026-85199-eclipse-aerios-self-orchestrator-path-traversal-in-rest-api","title":"Eclipse aeriOS Self-orchestrator path traversal in REST API","severity":"info","exploited":false,"published_at":"2026-09-03T15:17:39.937+00:00","url":"https://junglewise.ai/threats/cve-2026-85199-eclipse-aerios-self-orchestrator-path-traversal-in-rest-api"},{"cve":"CVE-2026-82180","cvss":7.5,"epss":0.0034,"slug":"cve-2026-82180-eclipse-arrowhead-certificatemqttfilter-certificate-validation","title":"Eclipse Arrowhead CertificateMqttFilter certificate validation bypass","severity":"info","exploited":false,"published_at":"2026-09-03T14:17:02.11+00:00","url":"https://junglewise.ai/threats/cve-2026-82180-eclipse-arrowhead-certificatemqttfilter-certificate-validation"},{"cve":"CVE-2026-80515","cvss":9.1,"epss":0.0047,"slug":"cve-2026-80515-eclipse-arrowhead-management-authorization-bypass-via-percent","title":"Eclipse Arrowhead management authorization bypass via percent-encoded paths","severity":"info","exploited":false,"published_at":"2026-09-03T14:17:01.83+00:00","url":"https://junglewise.ai/threats/cve-2026-80515-eclipse-arrowhead-management-authorization-bypass-via-percent"},{"cve":"CVE-2026-82955","cvss":7.4,"epss":0.0018,"slug":"cve-2026-82955-eclipse-aerios-krakend-insecure-jwks-retrieval-due-to-disabled","title":"Eclipse aeriOS KrakenD insecure JWKS retrieval due to disabled TLS verification","severity":"info","exploited":false,"published_at":"2026-09-02T15:17:44.86+00:00","url":"https://junglewise.ai/threats/cve-2026-82955-eclipse-aerios-krakend-insecure-jwks-retrieval-due-to-disabled"},{"cve":"CVE-2026-82958","cvss":8.2,"epss":0.0041,"slug":"cve-2026-82958-eclipse-ditto-implicitthingcreationmessagemapper-json-injection","title":"Eclipse Ditto ImplicitThingCreationMessageMapper JSON injection","severity":"info","exploited":false,"published_at":"2026-09-02T11:17:24.773+00:00","url":"https://junglewise.ai/threats/cve-2026-82958-eclipse-ditto-implicitthingcreationmessagemapper-json-injection"},{"cve":"CVE-2026-84175","cvss":6.5,"epss":0.004,"slug":"cve-2026-84175-eclipse-ditto-server-side-request-forgery-in-wot-thingmodel-fetch","title":"Eclipse Ditto server-side request forgery in WoT ThingModel fetch","severity":"info","exploited":false,"published_at":"2026-09-02T10:17:04.877+00:00","url":"https://junglewise.ai/threats/cve-2026-84175-eclipse-ditto-server-side-request-forgery-in-wot-thingmodel-fetch"},{"cve":"CVE-2026-18918","epss":0.0037,"slug":"cve-2026-18918-eclipse-lyo-oauth-authorization-bypass-in-2-legged-flows","title":"Eclipse Lyo OAuth authorization bypass in 2-legged flows","severity":"info","exploited":false,"published_at":"2026-08-28T12:16:27.15+00:00","url":"https://junglewise.ai/threats/cve-2026-18918-eclipse-lyo-oauth-authorization-bypass-in-2-legged-flows"},{"cve":"CVE-2026-79653","cvss":0,"epss":0.0047,"slug":"cve-2026-79653-eclipse-sw360-arbitrary-file-path-traversal-in-attachment-storage","title":"Eclipse SW360 arbitrary file path traversal in attachment storage","severity":"info","exploited":false,"published_at":"2026-08-27T17:20:47.887+00:00","url":"https://junglewise.ai/threats/cve-2026-79653-eclipse-sw360-arbitrary-file-path-traversal-in-attachment-storage"},{"cve":"CVE-2026-15803","cvss":6.5,"epss":0.0047,"slug":"cve-2026-15803-eclipse-rdf4j-xml-external-entity-processing-in-xml-parser","title":"Eclipse RDF4J XML External Entity processing in XML parser","severity":"info","exploited":false,"published_at":"2026-08-12T16:16:54.877+00:00","url":"https://junglewise.ai/threats/cve-2026-15803-eclipse-rdf4j-xml-external-entity-processing-in-xml-parser"},{"cve":"CVE-2026-6918","cvss":7.5,"epss":0.0038,"slug":"cve-2026-6918-eclipse-openj9-oob-read-and-crash-in-jitserver","title":"Eclipse OpenJ9 OOB read and crash in JITServer","severity":"high","exploited":false,"published_at":"2026-05-05T13:16:30.71+00:00","url":"https://junglewise.ai/threats/cve-2026-6918-eclipse-openj9-oob-read-and-crash-in-jitserver"},{"cve":"CVE-2026-24457","cvss":9.1,"epss":0.0062,"slug":"cve-2026-24457-eclipse-openmq-arbitrary-file-read-via-unsafe-configuration","title":"Eclipse OpenMQ arbitrary file read via unsafe configuration parsing","severity":"critical","exploited":false,"published_at":"2026-03-05T19:16:02.78+00:00","url":"https://junglewise.ai/threats/cve-2026-24457-eclipse-openmq-arbitrary-file-read-via-unsafe-configuration"},{"cve":"CVE-2025-12548","cvss":9,"epss":0.0133,"slug":"cve-2025-12548-eclipse-che-che-machine-exec-unauthenticated-remote-code","title":"Eclipse Che che-machine-exec unauthenticated remote code execution","severity":"critical","exploited":false,"published_at":"2026-01-13T16:15:55.527+00:00","url":"https://junglewise.ai/threats/cve-2025-12548-eclipse-che-che-machine-exec-unauthenticated-remote-code"},{"cve":"CVE-2025-67109","cvss":10,"epss":0.003,"slug":"cve-2025-67109-eclipse-cyclone-dds-certificate-expiration-bypass-in","title":"Eclipse Cyclone DDS certificate expiration bypass in authentication plugin","severity":"critical","exploited":false,"published_at":"2025-12-23T16:16:23.057+00:00","url":"https://junglewise.ai/threats/cve-2025-67109-eclipse-cyclone-dds-certificate-expiration-bypass-in"},{"cve":"CVE-2023-44487","cvss":5.3,"epss":1,"slug":"cve-2023-44487-http-2-rapid-reset-attack-vulnerability","title":"Multiple Vendors HTTP/2 denial of service via Rapid Reset attack","severity":"critical","exploited":true,"published_at":"2023-10-10T21:28:24+00:00","url":"https://junglewise.ai/threats/cve-2023-44487-http-2-rapid-reset-attack-vulnerability"}],"vendor":{"hub":true,"name":"Eclipse","slug":"eclipse","homepage":"https://www.eclipse.org/","description":"A non-profit foundation that manages the Eclipse ecosystem, including the Eclipse IDE and various open-source projects.","url":"https://junglewise.ai/threats/vendors/eclipse"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":7},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":4},{"week":"2026-09-14","critical":1,"exploited":0,"vulnerabilities":4},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":1}],"most_severe":[{"cve":"CVE-2023-44487","cvss":5.3,"epss":1,"slug":"cve-2023-44487-http-2-rapid-reset-attack-vulnerability","title":"Multiple Vendors HTTP/2 denial of service via Rapid Reset attack","severity":"critical","exploited":true,"published_at":"2023-10-10T21:28:24+00:00","url":"https://junglewise.ai/threats/cve-2023-44487-http-2-rapid-reset-attack-vulnerability"},{"cve":"CVE-2025-67109","cvss":10,"epss":0.003,"slug":"cve-2025-67109-eclipse-cyclone-dds-certificate-expiration-bypass-in","title":"Eclipse Cyclone DDS certificate expiration bypass in authentication plugin","severity":"critical","exploited":false,"published_at":"2025-12-23T16:16:23.057+00:00","url":"https://junglewise.ai/threats/cve-2025-67109-eclipse-cyclone-dds-certificate-expiration-bypass-in"},{"cve":"CVE-2026-24457","cvss":9.1,"epss":0.0062,"slug":"cve-2026-24457-eclipse-openmq-arbitrary-file-read-via-unsafe-configuration","title":"Eclipse OpenMQ arbitrary file read via unsafe configuration parsing","severity":"critical","exploited":false,"published_at":"2026-03-05T19:16:02.78+00:00","url":"https://junglewise.ai/threats/cve-2026-24457-eclipse-openmq-arbitrary-file-read-via-unsafe-configuration"},{"cve":"CVE-2026-78299","cvss":9.1,"epss":0.0054,"slug":"cve-2026-78299-eclipse-embedded-cdt-path-traversal-in-cmsis-pack-extraction","title":"Eclipse Embedded CDT path traversal in CMSIS-Pack extraction","severity":"critical","exploited":false,"published_at":"2026-09-14T13:18:46.87+00:00","url":"https://junglewise.ai/threats/cve-2026-78299-eclipse-embedded-cdt-path-traversal-in-cmsis-pack-extraction"},{"cve":"CVE-2025-12548","cvss":9,"epss":0.0133,"slug":"cve-2025-12548-eclipse-che-che-machine-exec-unauthenticated-remote-code","title":"Eclipse Che che-machine-exec unauthenticated remote code execution","severity":"critical","exploited":false,"published_at":"2026-01-13T16:15:55.527+00:00","url":"https://junglewise.ai/threats/cve-2025-12548-eclipse-che-che-machine-exec-unauthenticated-remote-code"},{"cve":"CVE-2026-6918","cvss":7.5,"epss":0.0038,"slug":"cve-2026-6918-eclipse-openj9-oob-read-and-crash-in-jitserver","title":"Eclipse OpenJ9 OOB read and crash in JITServer","severity":"high","exploited":false,"published_at":"2026-05-05T13:16:30.71+00:00","url":"https://junglewise.ai/threats/cve-2026-6918-eclipse-openj9-oob-read-and-crash-in-jitserver"},{"cve":"CVE-2026-80515","cvss":9.1,"epss":0.0047,"slug":"cve-2026-80515-eclipse-arrowhead-management-authorization-bypass-via-percent","title":"Eclipse Arrowhead management authorization bypass via percent-encoded paths","severity":"info","exploited":false,"published_at":"2026-09-03T14:17:01.83+00:00","url":"https://junglewise.ai/threats/cve-2026-80515-eclipse-arrowhead-management-authorization-bypass-via-percent"},{"cve":"CVE-2026-85199","cvss":8.6,"epss":0.0091,"slug":"cve-2026-85199-eclipse-aerios-self-orchestrator-path-traversal-in-rest-api","title":"Eclipse aeriOS Self-orchestrator path traversal in REST API","severity":"info","exploited":false,"published_at":"2026-09-03T15:17:39.937+00:00","url":"https://junglewise.ai/threats/cve-2026-85199-eclipse-aerios-self-orchestrator-path-traversal-in-rest-api"},{"cve":"CVE-2026-82958","cvss":8.2,"epss":0.0041,"slug":"cve-2026-82958-eclipse-ditto-implicitthingcreationmessagemapper-json-injection","title":"Eclipse Ditto ImplicitThingCreationMessageMapper JSON injection","severity":"info","exploited":false,"published_at":"2026-09-02T11:17:24.773+00:00","url":"https://junglewise.ai/threats/cve-2026-82958-eclipse-ditto-implicitthingcreationmessagemapper-json-injection"},{"cve":"CVE-2026-82180","cvss":7.5,"epss":0.0034,"slug":"cve-2026-82180-eclipse-arrowhead-certificatemqttfilter-certificate-validation","title":"Eclipse Arrowhead CertificateMqttFilter certificate validation bypass","severity":"info","exploited":false,"published_at":"2026-09-03T14:17:02.11+00:00","url":"https://junglewise.ai/threats/cve-2026-82180-eclipse-arrowhead-certificatemqttfilter-certificate-validation"}],"generated_at":"2026-09-26T20:07:00.238639+00:00","technologies":[{"name":"Eclipse Ankaios","slug":"ankaios","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/ankaios"}]}