Apache Vulnerabilities

Track Apache vulnerabilities including HTTP Server, Tomcat, Struts, and more. 30 CVE advisories sorted by CVSS score.

30
Total CVEs
13
Critical
17
High

CVE Advisories

critical 10
2026-04-27

Camel CoAP unauthenticated RCE (CVE-2026-33453) [PoC]

critical 9.9
2026-05-07

Azure Cassandra RCE, low-privilege (CVE-2026-33109)

critical 9.9
2026-04-27

Apache Camel JMS header bypass RCE (CVE-2026-40453)

critical 9.8
2026-05-01

Apache MINA IoBuffer RCE, patch bypass (CVE-2026-42778) [PoC]

critical 9.8
2026-05-01

MINA unauthenticated RCE via bad fix (CVE-2026-42779) [PoC]

critical 9.8
2026-04-28

Pony Mail admin takeover (CVE-2026-41873)

critical 9.8
2026-04-27

Camel deserialization RCE via JMS (CVE-2026-40860)

critical 9.8
2026-04-27

Apache MINA unauth RCE via deserialization (CVE-2026-41409)

critical 9.8
2026-04-27

Apache MINA unauth RCE via deserialization (CVE-2026-41635)

critical 9.8
2026-03-03

Apache RCE Vulnerability (CVE-2025-59059)

critical 9.4
2026-04-27

Apache Camel header injection via email (CVE-2026-33454)

critical 9.1
2026-05-06

Wicket session fixation, no patch yet (CVE-2026-40010)

critical 9.1
2026-04-20

Kafka OAuth JWT bypass grants unauth access (CVE-2026-33557)

high 8.8
2026-04-27

Camel MINA unauthenticated RCE (CVE-2026-40473)

high 8.8
2026-04-27

Camel RCE via deserialization (CVE-2026-40858)

high 8.8
2026-04-24

ActiveMQ code injection after auth bypass (CVE-2026-40466)

high 8.8
2026-04-24

ActiveMQ RCE via Spring XML (CVE-2026-41044)

high 8.8
2026-04-13

Airflow webserver code execution by Dag Authors (CVE-2026-33858)

high 8.8
2026-04-13

Storm RCE via Kerberos credential deserialization (CVE-2026-35337)

high 8.8
2026-04-07

ActiveMQ RCE exploited in the wild (CVE-2026-34197) [PoC]

high 8.2
2026-04-28

Apache Thrift OOB read leaks data (CVE-2026-41604)

high 8.1
2026-04-24

Apache DolphinScheduler tenant bypass (CVE-2026-23902)

high 8.1
2026-03-17

Airflow lets tasks read HITL data (CVE-2026-30911)

high 7.5
2026-05-01

Neethi denial of service via XML (CVE-2026-42402)

high 7.5
2026-05-01

Apache Neethi stack overflow via circular refs (CVE-2026-42403)

high 7.5
2026-04-28

Apache Thrift c_glib server crash (CVE-2025-48431)

high 7.5
2026-04-28

Apache Thrift integer overflow crash (CVE-2026-41602)

high 7.5
2026-04-28

Apache Thrift Node.js stack overflow (CVE-2026-41636)

high 7.5
2026-04-10

ActiveMQ TLSv1.3 memory DoS (CVE-2026-39304)

high 7.5
2026-03-17

Airflow session token hijack (CVE-2026-28779)

Related News

Browse all vendors

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.