[UPDATE] [medium] Apache CXF: Multiple vulnerabilities
A remote, authenticated attacker can exploit multiple vulnerabilities in Apache CXF to bypass security measures, conduct XML External Entity attacks, manipulate data, or disclose confidential information.
CSIRTS triage
- What
- A remote, authenticated attacker can exploit multiple vulnerabilities in Apache CXF to bypass security measures and disclose confidential information.
- Who is affected
- Authenticated users of Apache CXF are affected.
- Urgency
- Remediation is medium urgency as it can lead to information disclosure.
- Action
- Update to the latest version of Apache CXF.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CXF
Get an email when a new CXF advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1895
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-498750.53% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 42% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-506230.37% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 30% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-506270.45% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 37% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-506280.68% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 49% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-506290.47% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-506300.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-506310.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-506320.65% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 48% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-506330.86% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 55% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-506340.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-49875 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-50623 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-50627 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-50628 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-50629 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-50630 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-50631 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-50632 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-50633 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-50634 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-50645 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[NEW] [medium] IBM WebSphere Application Server: Multiple vulnerabilities enable Denial of Servicecert-bund
- unknownexploitedMultiple vulnerabilities in IBM products (August 21, 2026)cert-fr-avis
- unknownexploitedMultiple vulnerabilities in IBM products (August 14, 2026)cert-fr-avis
- unknownMultiple vulnerabilities in IBM products (August 07, 2026)cert-fr-avis
- unknownMultiple vulnerabilities in IBM products (July 17, 2026)cert-fr-avis
- unknownMultiple vulnerabilities in IBM products (July 10, 2026)cert-fr-avis
- unknownMultiple vulnerabilities in IBM products (July 3, 2026)cert-fr-avis
- unknownIBM WebSphere Products Multiple Vulnerabilitieshkcert
- criticalGHSA-qp3f-rvj8-46c8: Apache CXF JNDI Injection vulnerability in DispatchMDBMessageListenerImplghsa
- highGHSA-ghvc-7hp8-2g2v: Apache cxf-core: No restriction on attachment headers per messageghsa
- mediumGHSA-33j8-j763-4fv5: Apache CXF: WS JSON request filter trusts metadata from an unvalidated first signature en…ghsa
- criticalGHSA-93g8-qqv3-mrx8: Apache CXF has JNDI Injection Vulnerability in JMSConfigFactoryghsa
Recent advisories for Apache CXF
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- medium[NEW] [medium] Apache CXF: Multiple Vulnerabilitiescert-bund · 2026-08-18
- highCVE-2026-68481: In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still decrypt succes…nvd · 2026-08-06
- criticalCVE-2026-68079: In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeem…nvd · 2026-08-06
- criticalCVE-2026-65583: Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without en…nvd · 2026-08-06
- criticalCVE-2026-63687: Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authori…nvd · 2026-08-06
- criticalCVE-2026-61466: In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts …nvd · 2026-08-06
More from CERT-Bund (BSI) Security Advisories
- high[NEW] [high] Linux Kernel: Multiple vulnerabilities2026-08-25
- medium[NEW] [medium] libTIFF: Multiple Vulnerabilities2026-08-25
- high[NEW] [high] Contao: Multiple Vulnerabilities2026-08-25
- medium[NEW] [medium] Django: Multiple Vulnerabilities2026-08-25
- high[NEW] [high] Red Hat Enterprise Linux (Apicurio Registry): Multiple Vulnerabilities2026-08-25