THE Apache Fory project reported four vulnerabilities on July 21, 2026, with three rated as critical and one as moderate. The highest severity is 9.8 (CVSSv3). Key flaws include a class-registration bypass in Java, type confusion in C++, and a use-after-free issue in Rust. Version 1.4.0 patches all vulnerabilities, with no confirmed exploitation yet.
Users are advised to update to the latest version to mitigate risks, as deserialization bugs can pose significant security threats across multiple language implementations.