Apache

Apache bRPC Vulnerability Enables Remote Command Injection Attacks

Apache bRPC, a widely used open-source Remote Procedure Call (RPC) framework, contains a critical remote command-injection vulnerability in its built-in heap profiler service, allowing...

Critical Apache Struts 2 Vulnerability Allows Attackers to Steal Sensitive Data

A newly disclosed vulnerability in Apache Struts 2's XWork component poses a significant threat to Java web applications worldwide. The flaw, tracked as CVE-2025-68493...

Apache NuttX Flaw Allows Remote Attackers to Crash Embedded Systems

The Apache Software Foundation has released a security advisory addressing a critical memory corruption vulnerability in the Apache NuttX Real-Time Operating System (RTOS). Tracked...

Over 500 Apache Tika Instances Exposed Online to Critical XXE Attacks

A critical XML External Entity (XXE) injection vulnerability in Apache Tika has exposed over 500 public-facing servers worldwide to potential exploitation. CVE-2025-66516, carrying the...

Critical Apache Tika Core Vulnerability Exploited Through Malicious PDF Uploads

A critical XML External Entity (XXE) injection vulnerability in Apache Tika has been formally catalogued as CVE-2025-66516, significantly expanding the scope of affected systems...

Popular

Subscribe