Vulnerability Bulletins

CVE-2026-44618

   
Affected software APACHE
 
Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.

Link:

https://nvd.nist.gov/vuln/detail/CVE-2026-44618