Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 Apache CXF's JMS transport component is vulnerable to deserialization of untrusted data via JMS ObjectMessage bodies. This vulnerability allows an attacker who can send messages to the JMS destination to submit malicious serialized objects, potentially causing denial of service or remote code execution if a suitable gadget class is present. The issue is fixed by disabling ObjectMessage deserialization by default and providing a configuration option to re-enable it if necessary. Users should upgrade to Apache CXF versions 4.2.3, 4.1.8, or 3.6.12 to address this vulnerability. Join the discussion | CVE Database V5 | 08/06/2026, 10:23:23 UTC Added: 08/06/2026, 11:12:04 UTC |
0 CVE-2026-50632 is a high-severity vulnerability in Apache CXF related to improper input validation and deserialization of untrusted JMS configuration data. It stems from an incomplete fix of a previous issue (CVE-2026-44417) and allows untrusted users who can configure JMS to achieve arbitrary code execution, potentially leading to full system compromise. The vulnerability affects multiple Apache CXF versions prior to fixed releases 4.2.2, 4.1.7, and 3.6.12. Mitigation involves restricting JMS configuration access to trusted administrators only. Official patches are available in the specified fixed versions. Join the discussion | CVE Database V5 | 06/12/2026, 09:00:48 UTC Added: 06/12/2026, 09:54:39 UTC |
0 The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lead to code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF. Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue. Join the discussion | CVE Database V5 | 05/22/2026, 12:17:25 UTC Added: 05/22/2026, 12:44:48 UTC |
Showing 1 to 3 of 3 results