CVE-2026-66909
published 2026-08-06CVE-2026-66909: Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place. Any…
PriorityP263critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.67%
49.6th percentile
Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place. Any attacker able to place a message on the service's JMS destination can submit a malicious serialized object, leading to denial of service or, if a suitable gadget class is on the classpath, remote code execution. The fix disables ObjectMessage deserialization by default, with a configuration switch to re-enable it if needed. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | cxf | < 3.6.12 | 3.6.12 |
| apache | cxf | — | — |
| apache | cxf | >= 4.0.0 < 4.1.8 | 4.1.8 |
| apache | cxf | >= 4.2.0 < 4.2.3 | 4.2.3 |
| apache_software_foundation | apache_cxf | < 3.6.12 | 3.6.12 |
| apache_software_foundation | apache_cxf | >= 4.0.0 < 4.1.8 | 4.1.8 |
| apache_software_foundation | apache_cxf | >= 4.2.0 < 4.2.3 | 4.2.3 |
| eap74-els-openjdk11-openshift-rhel8 | eap74-els-openjdk11-openshift-rhel8 | — | — |
| eap74-els-openjdk17-openshift-rhel8 | eap74-els-openjdk17-openshift-rhel8 | — | — |
| eap74-els-openjdk8-openshift-rhel8 | eap74-els-openjdk8-openshift-rhel8 | — | — |
| jboss-eap-7-eap74-els-openjdk17-openshift-rhel8 | jboss-eap-7-eap74-els-openjdk17-openshift-rhel8 | — | — |
| jboss-eap-7-eap74-els-openjdk8-openshift-rhel8 | jboss-eap-7-eap74-els-openjdk8-openshift-rhel8 | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
org.apache.cxf/cxf: Apache CXF: Remote Code Execution via unsafe deserialization of JMS ObjectMessage
vendor_redhat·2026-08-06·CVSS 9.8
CVE-2026-66909 [CRITICAL] CWE-502 org.apache.cxf/cxf: Apache CXF: Remote Code Execution via unsafe deserialization of JMS ObjectMessage
org.apache.cxf/cxf: Apache CXF: Remote Code Execution via unsafe deserialization of JMS ObjectMessage
Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place. Any attacker able to place a message on the service's JMS destination can submit a malicious serialized object, leading to denial of service or, if a suitable gadget class is on the classpath, remote code execution. The fix disables ObjectMessage deserialization by default, with a configuration switch to re-enable it if needed. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
A flaw was found in Apache CXF. The Java Message Service (JMS) transport component improperly deserializes inbound JMS O
GHSA
Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place.
ghsa_unreviewed·2026-08-06
CVE-2026-66909 [CRITICAL] CWE-502 Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place.
Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place. Any attacker able to place a message on the service's JMS destination can submit a malicious serialized object, leading to denial of service or, if a suitable gadget class is on the classpath, remote code execution. The fix disables ObjectMessage deserialization by default, with a configuration switch to re-enable it if needed. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
No detection rules found.
No public exploits indexed.
2026-08-06
Published