CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-25688

mediumCVSS 6.1covered by 1 sourcefirst seen 2026-06-09
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue.

⚡ Watch CVE-2026-25688

Get an email if CVE-2026-25688 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-25688

CVE.org record

Embed the live status

CVE-2026-25688 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-25688 status](https://www.csirts.com/badge/CVE-2026-25688)](https://www.csirts.com/cve/CVE-2026-25688)