Vulnerability intelligence
CVE-2026-50633
A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able to manipulate the JCA deployment descriptor (ra.xml) or runtime activation parameters. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fixes this issue.
CVSS Score
8.1
High
EPSS — Exploit Probability
0.9%
Riskier than 56% of all CVEs · checked 2026-09-10
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
Patch available
Vendor fix published
1 article across 1 outlet · first covered Jun 13, 2026 · latest Jun 13, 2026
Coverage timeline
-
Important Apache CXF Vulnerabilities Demand Immediate Actionsecurityonline.info · Jun 13, 2026