THREAT OPS › Threat News › [NVD] CVE-2026-50632 (HIGH 8.1) — A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF. Users are recommended to
[NVD] CVE-2026-50632 (HIGH 8.1) — A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF. Users are recommended to
CVE-2026-50632 CVSS: 8.1 HIGH Published: 2026-06-12T10:16:23.183
A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fi
Indicators of compromise
- CVE-2026-50632cve
- CVE-2026-44417cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-50632