Cyber Security News·10d agoApache Syncope Vulnerabilities Allow Attackers to Execute Malicious Code and Bypass Controls#apache-syncope#code-injection#groovy 3 min3
oss-security·12d agoCVE-2026-87785: Apache Syncope: JWT subject spoofing#apache-syncope#authentication-bypass#cveCVE-2026-87785
oss-security·12d agoCVE-2026-87779: Apache Syncope: AES Secret Key disclosure via log output#aes#apache-syncope#cveCVE-2026-877791
oss-security·12d ago highCVE-2026-77147: Apache Syncope: Groovy Sandbox escape for empty CommandArgs#apache-syncope#code-injection#cve-2026-77147CVE-2026-77147
oss-security·12d agoCVE-2026-77051: Apache Syncope: SQL injection via unsanitized entityKey and opEvent in Audit Events search#apache-syncope#audit#cve-2026-77051CVE-2026-77051
oss-security·12d agoCVE-2026-75030: Apache Syncope: Incomplete authorization checks for Group members deprovisioning#apache-syncope#authorization#cve-2026-75030CVE-2026-750301