[UPDATE] [mittel] Apache CXF: Mehrere Schwachstellen
Ein Angreifer kann mehrere Schwachstellen in Apache CXF ausnutzen, um beliebigen Programmcode auszuführen, um seine Privilegien zu erhöhen, um einen Denial of Service Angriff durchzuführen, und um Sicherheitsvorkehrungen zu umgehen.
CSIRTS triage
- What
- Multiple vulnerabilities in Apache CXF enable arbitrary code execution, privilege escalation, denial of service, and authentication bypass.
- Who is affected
- Apache CXF deployments using affected versions.
- Urgency
- High urgency; multiple classes including remote code execution represent significant exploitation risk.
- Action
- Apply security patches for CVE-2026-54225, CVE-2026-57817, CVE-2026-57818, CVE-2026-57819, CVE-2026-61466, CVE-2026-63687, CVE-2026-64958, CVE-2026-65432 when released by Apache.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CXF
Get an email when a new CXF advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2682
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-542250.47% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-578170.45% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-578180.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 28% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-578190.47% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-614660.42% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 36% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-636870.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-649580.41% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-654320.41% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-669090.67% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 50% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-54225 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-57817 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-57818 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-57819 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-61466 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-63687 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-64958 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-65432 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-66909 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[UPDATE] [mittel] RealObjects PDFreactor: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriffcert-bund
- unknownexploitedMultiple vulnerabilities in IBM products (August 14, 2026)cert-fr-avis
- criticalCVE-2026-63687: Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authori…nvd
- criticalCVE-2026-61466: In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts …nvd
- highCVE-2026-57818: A race condition in JCacheCodeDataProvider allows an attacker to redeem a single authorization…nvd
- criticalCVE-2026-66909: Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native…nvd
- highCVE-2026-65432: Apache CXF reads a top-level WSDL through its hardened StaxUtils path, which disables XML DTDs…nvd
- highCVE-2026-64958: An incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial of se…nvd
- highCVE-2026-57819: Apache CXF allows to set a limit on the number of form parameters in a JAX-RS message via the …nvd
- highCVE-2026-57817: The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` para…nvd
- highCVE-2026-54225: Apache CXF allows to control the maximum attachment size via the "attachment-max-size". Prior …nvd
Recent advisories for Apache CXF
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- medium[UPDATE] [mittel] Apache CXF: Mehrere Schwachstellencert-bund · 2026-09-09
- highCVE-2026-68481: In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still decrypt succes…nvd · 2026-08-06
- criticalCVE-2026-68079: In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeem…nvd · 2026-08-06
- criticalCVE-2026-65583: Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without en…nvd · 2026-08-06
- criticalCVE-2026-63687: Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authori…nvd · 2026-08-06
- criticalCVE-2026-61466: In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts …nvd · 2026-08-06
More from CERT-Bund (BSI) Security Advisories
- medium[NEU] [mittel] Microsoft Edge: Schwachstelle ermöglicht Cross-Site Scripting2026-09-14
- medium[NEU] [mittel] Citrix Systems Workspace App Windows: Mehrere Schwachstellen ermöglichen nicht spezifizierten A…2026-09-14
- medium[NEU] [mittel] wpa_supplicant: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen2026-09-14
- medium[NEU] [mittel] WP Royal Royal Elementor Addons: Schwachstelle ermöglicht Offenlegung von Informationen2026-09-14
- low[UPDATE] [niedrig] 7-Zip: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen2026-09-14