FOUR new vulnerabilities in Apache NiFi (versions prior to 2.11.0) allow code execution, authorization bypass, and system resource consumption. Users are urged to update to version 2.11.0 to protect their data pipelines. Key vulnerabilities include CVE-2026-68981 (8.8 severity), causing uncontrolled resource consumption, and CVE-2026-62354, which allows incorrect authorization for validation requests.
No exploits have been confirmed yet, but these flaws could significantly impact operations and expose sensitive information. Immediate action is recommended to secure installations.