CVE-2026-66909

cxf: Deserialization of Untrusted Data (CVE-2026-66909)

criticalEPSS 1.2%

Affected

  • apache/cxf lt *..3.6.12
  • apache/cxf between 4.0.0..4.1.8
  • apache/cxf between 4.2.0..4.2.3

Description

A flaw was found in Apache CXF. The Java Message Service (JMS) transport component improperly deserializes inbound JMS ObjectMessages without type restrictions. A remote attacker can exploit this by sending a specially crafted message to the service's JMS destination. This vulnerability could lead to a denial of service or, in certain configurations, enable remote code execution on the affected system.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

apachecxf
4.0.0 – 4.1.84.2.0 – 4.2.33.6.12fixed from 3.6.12

Metrics

9.8
Source: cna-v3
65.9 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
Show all metrics
Severity
critical
no public PoC known
1.2 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2026-08-06 10:23 UTC
CWE-502

Weakness classes (CWE)

  • CWE-502Base

    Deserialization of Untrusted Data

    The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-08-07 00:16 UTC· af854a3a-2127-422b-91ae-364da2661108
    • Reference: http://www.openwall.com/lists/oss-security/2026/08/06/18
  2. Initial Analysis2026-08-06 18:41 UTC· nvd@nist.gov
    • CPE Configuration: OR *cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:* versions up to (excluding) 3.6.12 *cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:* versions from (including) 4.0.0 up to (excluding) 4.1.8 *cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:* versions from (including) 4.2.0 up to (excluding) 4.2.3
    • Reference Type: Apache Software Foundation: https://lists.apache.org/thread/lr5d4tg6tf7j29jmw8wt242oowonjqpx Types: Mailing List, Vendor Advisory
  3. CVE Modified2026-08-06 16:16 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    • SSVC: {"id":"CVE-2026-66909","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical…
  4. New CVE Received2026-08-06 11:16 UTC· security@apache.org
    • Affected: Apache CXF
    • Description: Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place. Any attacker able to place a message on the service's JMS destination can submit a malicious serialized object, leading to denial of service or, if a suitable gadget class is on the classpath, remote code execution. The fix disables ObjectMessage deserialization by default, with a configuration switch to re-enable it if needed. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
    • CWE: CWE-502
    • Reference: https://lists.apache.org/thread/lr5d4tg6tf7j29jmw8wt242oowonjqpx

Linked advisories