All CVEs
Vulnerability intelligence

CVE-2026-50633

Apache Software Foundation Apache CXF CWE-20

A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able to manipulate the JCA deployment descriptor (ra.xml) or runtime activation parameters. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fixes this issue.

CVSS Score
8.1
High
EPSS — Exploit Probability
0.9%
Riskier than 56% of all CVEs · checked 2026-09-10
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
Patch available
Vendor fix published
NVD entry Vendor patch PoC / advisory

1 article across 1 outlet · first covered Jun 13, 2026 · latest Jun 13, 2026

Coverage timeline

Related CVEs — Apache Software Foundation