Known Vulnerabilities for products from Apache
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Apache".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-67178 json | Not Provided | 2026-07-28 | 2026-07-28 | |
| CVE-2026-66756 json | Not Provided | 2026-07-30 | 2026-07-30 | |
| CVE-2026-66755 json | Not Provided | 2026-07-30 | 2026-07-30 | |
| CVE-2026-66713 json | Not Provided | 2026-07-28 | 2026-07-29 | |
| CVE-2026-66391 json | Not Provided | 2026-07-27 | 2026-07-28 | |
| CVE-2026-66390 json | Not Provided | 2026-07-27 | 2026-07-28 | |
| CVE-2026-66299 json | Not Provided | 2026-07-28 | 2026-07-28 | |
| CVE-2026-66144 json | Although remote policy references are not retrieved during policy normalization, if they are manually retrieved via the API i... | Not Provided | 2026-07-24 | 2026-07-27 |
| CVE-2026-66143 json | It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2 via... | Not Provided | 2026-07-24 | 2026-07-27 |
| CVE-2026-66142 json | Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested struct... | Not Provided | 2026-07-24 | 2026-07-27 |
| CVE-2026-66053 json | Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings. This issue affects Apa... | Not Provided | 2026-07-27 | 2026-07-27 |
| CVE-2026-64609 json | Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-band zero-copy deserialization is used, readAlignedVarUint... | Not Provided | 2026-07-21 | 2026-07-27 |
| CVE-2026-64606 json | Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lambda de... | Not Provided | 2026-07-21 | 2026-07-27 |
| CVE-2026-63071 json | Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for ... | Not Provided | 2026-07-20 | 2026-07-27 |
| CVE-2026-62418 json | Low-privileged authenticated Server-Side Request Forgery (SSRF) vulnerability in Apache Syncope via Connectors and Resources... | Not Provided | 2026-07-20 | 2026-07-27 |
| CVE-2026-62393 json | Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kylin. Improper authorization in job inf... | Not Provided | 2026-07-14 | 2026-07-15 |
| CVE-2026-62392 json | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. A b... | Not Provided | 2026-07-14 | 2026-07-15 |
| CVE-2026-62390 json | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin. A backend... | Not Provided | 2026-07-14 | 2026-07-14 |
| CVE-2026-62183 json | Improper Privilege Management vulnerability in Apache Syncope. When: * the all-Java user workflow adapter is configured, or... | Not Provided | 2026-07-20 | 2026-07-27 |
| CVE-2026-60080 json | Use After Free vulnerability in the Rust deserialization logic of Apache Fory. This issue affects Apache Fory from 0.13.0 thr... | Not Provided | 2026-07-21 | 2026-07-27 |
Known software with vulnerabilities from Apache
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Apache | Accumulo | 1.10.0 |
| Application | Apache | Activemq | - |
| Application | Apache | Activemq Apollo | 1.0 |
| Application | Apache | Activemq Artemis | - |
| Application | Apache | Airflow | 0.1 |
| Application | Apache | Allura | 1.0.0 |
| Application | Apache | Ambari | 0.9 |
| Application | Apache | Amqp 0-x Jms Client | 6.0.3 |
| Application | Apache | Amqp Jms Client | 0.9.0 |
| Application | Apache | Ant | 1.1 |
| Application | Apache | Apache-ssl | 1.37 |
| Application | Apache | Apache Test | - |
| Application | Apache | Apisix | 1.2 |
| Application | Apache | Apr-util | 0.9.1 |
| Application | Apache | Archiva | 0.9 |
| Application | Apache | Arrow | 0.1.0 |
| Application | Apache | Asterixdb | - |
| Application | Apache | Atlas | 0.5.0 |
| Application | Apache | Axis | - |
| Application | Apache | Axis2 | - |