Vulnerability intelligence
CVE-2026-50633
A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able to manipulate the JCA deployment descriptor (ra.xml) or runtime activation parameters. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.
CVSS Score
8.1
High
EPSS — Exploit Probability
0.8%
Riskier than 54% of all CVEs
Exploitation
Not in CISA KEV
No federal exploitation record
Remediation
Patch available
Vendor fix published
1 article across 1 outlet · first covered Jun 13, 2026 · latest Jun 13, 2026
Coverage timeline
-
Important Apache CXF Vulnerabilities Demand Immediate Actionsecurityonline.info · Jun 13, 2026