Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
open-source-dependency-vulnerabilitywidely-deployed-product-advisoryinternet-facing-service-vulnerabilityidentity-authentication-vulnerability

Apache CXF Patches LDAP Injection, XXE, and Incomplete-Fix RCE Flaws

Updated 27d agoFirst seen May 26, 20262 sources

The Apache Software Foundation released security updates for Apache CXF to fix three newly disclosed vulnerabilities affecting enterprise deployments of the services framework. The flaws include CVE-2026-44930, an LDAP injection issue in the XKMS LDAP certificate repository that can let attackers manipulate backend search filters and retrieve arbitrary digital certificates, potentially enabling impersonation, interception of encrypted communications, and lateral movement. Apache also addressed an XXE flaw in WS-Transfer caused by insecure XML parser configuration, which could expose sensitive files and support internal network mapping, as well as a possible remote code execution condition tied to an incomplete fix for an older JMS-related bug.

Affected releases include 4.2.0, 4.0.0 through 4.1.5, and older branches before 3.6.11. Apache published patched versions 4.2.1, 4.1.6, and 3.6.11, and guidance urges organizations to upgrade immediately, review LDAP access controls, monitor certificate access activity, and reduce exposure of XKMS components where possible. The disclosures indicate that while the LDAP flaw does not itself provide code execution, the combined set of weaknesses could materially affect trust infrastructure and server security in vulnerable environments.

Share:
Apache CXF Patches LDAP Injection, XXE, and Incomplete-Fix RCE Flaws
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

2 events from the most recent confirmed update back to the earliest known activity.

2 EVENTS
May 26, 202628d ago

Apache releases CXF updates fixing three newly disclosed vulnerabilities

The Apache Software Foundation released security updates for Apache CXF addressing three flaws: an LDAP injection issue in the XKMS LDAP certificate repository, an XXE vulnerability in WS-Transfer, and a remote code execution risk caused by an incomplete fix for an older JMS-related bug. Recommended fixed versions are 4.2.1, 4.1.6, and 3.6.11, covering affected 4.2.0, 4.0.0-4.1.5, and older pre-3.6.11 releases.

May 22, 20261mo ago

Apache publicly discloses CXF LDAP injection flaw CVE-2026-44930

Apache CXF publicly disclosed CVE-2026-44930 on the Apache developer mailing list. The flaw affects the XKMS LDAP certificate repository and can let attackers manipulate LDAP queries to retrieve arbitrary digital certificates.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

5 LINKEDOpen in app
Affected products
1 linked
Apache-Cxf
Organizations
1 linked
Apache Software Foundation
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.