cbcvebase.
CVE-2026-44618
published 2026-05-22

CVE-2026-44618: Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks. Users are recommended to upgrade to versions…

PriorityP429medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.34%
26.0th percentile
Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks. Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.

Affected

6 ranges
VendorProductVersion rangeFixed in
apachecxf< 3.6.113.6.11
apachecxf
apachecxf>= 4.0.0 < 4.1.64.1.6
apache_software_foundationapache_cxf< 3.6.113.6.11
apache_software_foundationapache_cxf>= 4.0.0 < 4.1.64.1.6
apache_software_foundationapache_cxf>= 4.2.0 < 4.2.14.2.1

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
cvelistv5v3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.