Apache vulnerabilities
150 CVEs tracked
Recent reporting highlights several vulnerabilities within the Apache vendor ecosystem, notably affecting Apache Fory and Apache Neethi. Critical issues in Apache Fory include a Use After Free (CVE-2026-60080) in Rust deserialization and a deserialization bypass (CVE-2026-64606). Apache Neethi is susceptible to denial-of-service attacks via resource consumption (CVE-2026-66143) and uncontrolled recursion (CVE-2026-66142). Additionally, multiple low-to-medium severity flaws like buffer overflow (CVE-2026-45811) and out-of-bounds write (CVE-2026-45813) were identified in Apache NimBLE. Defenders should prioritize patching Apache Fory to version 1.4.0 and Apache Neethi to version 3.2.3, along with applying available updates for Apache NimBLE.
Azərbaycanca: Son hesabatlara əsasən, Apache vendoru altında bir neçə kritik boşluq müşahidə olunur. Xüsusilə Apache Fory məhsulunda aşkarlanan Use After Free (CVE-2026-60080) və deserialization (CVE-2026-64606) zəiflikləri, həmçinin Apache Neethi-də resurs tükənməsinə səbəb ola biləcək xidmət əngəli (CVE-2026-66143) və idarəolunmaz rekursiya (CVE-2026-66142) problemləri diqqət çəkir. Apache NimBLE-də isə buffer overflow (CVE-2026-45811) və out-of-bounds write (CVE-2026-45813) kimi bir neçə aşağı və orta şiddətli zəiflik qeydə alınıb. Müdafiəçilər xüsusilə Apache Fory (1.4.0 versiyasına) və Apache Neethi (3.2.3 versiyasına) yeniləmələrini prioritetləşdirməli, həmçinin NimBLE üçün buraxılmış yamaları tətbiq etməlidirlər.
This vendor's CVEs60
- CVE-2026-34486KEVEPSS 99%
- CVE-2026-73635EPSS 0.45%
- CVE-2026-73634EPSS 0.43%
- CVE-2026-73633EPSS 0.60%
- CVE-2026-73632EPSS 0.26%
- CVE-2026-73631EPSS 0.26%
- CVE-2026-73240EPSS 0.54%
- CVE-2026-73239EPSS 0.34%
- CVE-2026-73238EPSS 0.43%
- CVE-2026-73237EPSS 0.43%
- CVE-2026-71560EPSS 0.42%
- CVE-2026-71559EPSS 0.44%
- CVE-2026-71558EPSS 0.53%
- CVE-2026-71290EPSS 0.24%
- CVE-2026-68871EPSS 0.33%
- CVE-2026-68870EPSS 0.22%
- CVE-2026-68481EPSS 0.43%
- CVE-2026-68079EPSS 0.40%
- CVE-2026-68078EPSS 0.41%
- CVE-2026-68077EPSS 0.42%
- CVE-2026-68075EPSS 0.42%
- CVE-2026-68074EPSS 0.49%
- CVE-2026-68073EPSS 0.48%
- CVE-2026-68060EPSS 0.48%
- CVE-2026-67592EPSS 0.48%
- CVE-2026-67591EPSS 0.42%
- CVE-2026-67590EPSS 0.49%
- CVE-2026-67589EPSS 0.49%
- CVE-2026-67588EPSS 0.48%
- CVE-2026-67555EPSS 0.41%
- CVE-2026-67554EPSS 0.41%
- CVE-2026-67553EPSS 0.41%
- CVE-2026-67552EPSS 0.48%
- CVE-2026-67551EPSS 0.49%
- CVE-2026-67465EPSS 0.49%
- CVE-2026-67178EPSS 0.49%
- CVE-2026-66909EPSS 0.67%
- CVE-2026-66756EPSS 0.45%
- CVE-2026-66713EPSS 1%
- CVE-2026-66391EPSS 0.40%
- CVE-2026-66390EPSS 0.36%
- CVE-2026-66299EPSS 0.53%
- CVE-2026-66277EPSS 0.42%
- CVE-2026-66276EPSS 0.42%
- CVE-2026-66275EPSS 0.42%
- CVE-2026-66274EPSS 0.49%
- CVE-2026-66273EPSS 0.43%
- CVE-2026-66257EPSS 0.43%
- CVE-2026-66143EPSS 0.51%
- CVE-2026-66142EPSS 0.48%
- CVE-2026-66053EPSS 0.21%
- CVE-2026-65948EPSS 0.35%
- CVE-2026-65945EPSS 0.36%
- CVE-2026-65942EPSS 0.33%
- CVE-2026-65583EPSS 0.26%
- CVE-2026-65432EPSS 0.41%
- CVE-2026-65100EPSS 0.35%
- CVE-2026-64958EPSS 0.41%
- CVE-2026-64640EPSS 0.37%
- CVE-2026-64606EPSS 0.72%
Showing the top 60 of 150 — known-exploited and newest first.
This hub is built from skopnix's own reporting on Apache: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.