Apache

Apache Syncope Vulnerability Allows Attackers to Hijack Active User Sessions

Apache Syncope, a widely deployed open-source identity and access management platform, has disclosed a critical XML External Entity (XXE) vulnerability affecting its Console component....

Apache bRPC Vulnerability Enables Remote Command Injection Attacks

Apache bRPC, a widely used open-source Remote Procedure Call (RPC) framework, contains a critical remote command-injection vulnerability in its built-in heap profiler service, allowing...

Critical Apache Struts 2 Vulnerability Allows Attackers to Steal Sensitive Data

A newly disclosed vulnerability in Apache Struts 2's XWork component poses a significant threat to Java web applications worldwide. The flaw, tracked as CVE-2025-68493...

Apache NuttX Flaw Allows Remote Attackers to Crash Embedded Systems

The Apache Software Foundation has released a security advisory addressing a critical memory corruption vulnerability in the Apache NuttX Real-Time Operating System (RTOS). Tracked...

Over 500 Apache Tika Instances Exposed Online to Critical XXE Attacks

A critical XML External Entity (XXE) injection vulnerability in Apache Tika has exposed over 500 public-facing servers worldwide to potential exploitation. CVE-2025-66516, carrying the...

Popular

Subscribe