Help Net Security·2d agoAzul AI Assistant helps teams find Java licensing and security risks#azul#java#jvmTools 5 min
oss-security·5d ago highCVE-2026-94301: Apache MINA: CVE-2026-47065 resolveProxyClass fix missing from 2.0.X and 2.1.X branches (2.0.30 / 2.1.14) ZDRES-232#apache-mina#cve-2026-94301#cve-2026-47065CVE-2026-94301 2 sources
oss-security·8d agoCVE-2026-91867: Apache Neethi: Remote policy fetch lacks a total timeout, allowing a slow server to hang the request indefinitely#apache-neethi#cve#denial-of-serviceCVE-2026-91867 5 sources
oss-security·10d ago highCVE-2026-76646: Apache MyFaces: Denial of Service via Unbounded Request Parsing#apache#cve-2026-76646#denial-of-serviceCVE-2026-76646 2 sources
oss-security·10d ago highCVE-2026-87976: Apache NiFi Registry: Improper Limitation of Pathname in Persisted Extension Bundles#apache#extension-bundles#javaCVE-2026-87976 5 sources1
oss-security·13d agoCVE-2026-82426: Apache Storm Nimbus: Arbitrary File Read on Nimbus via Unvalidated Uploaded Jar Location#apache#arbitrary-file-read#cveCVE-2026-824262
oss-security·15d agoCVE-2026-82617: Apache OpenNLP: ReDoS / stack exhaustion in RegexNameFinderFactory built-in EMAIL and URL patterns#apache#denial-of-service#javaCVE-2026-82617 2 sources2
arXiv cs.CR·16d agoIDORacle: Template-Guided SQL-Sink Mediation for Object-Level Authorization in Java Applications#access-control#authorization#bolaResearch1
arXiv cs.AI / cs.LG / cs.CL·17d agoRetrofitting Code Using LLMs to Support Exceptional Behavior#code-generation#exception-handling#javaAI research2
oss-security·18d agoCVE-2026-74761: Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Spoofing of RemoveSubscription clientId#apache-activemq#cve-2026-74761#javaCVE-2026-747611
oss-security·18d agoCVE-2026-41869: Apache Nutch: Unauthenticated forced shutdown and job interruption in Nutch Server (Nutch REST API)#apache#cve-2026-41869#denial-of-serviceCVE-2026-41869 3 sources
oss-security·18d agoCVE-2026-84939: Apache FreeMarker: A malformed locale may be exploitable for path traversal attacks#apache#cve-2026-84939#freemarkerCVE-2026-84939
oss-security·20d agoCVE-2026-78254: Apache Ant: Path traversal in ftp and scp tasks allows arbitrary file write#apache#apache-ant#build-toolsCVE-2026-782541
Full Disclosure·23d ago highPayara 7.2026.1.RC1 Remote Code Execution via Server-Side Includes #exec Directive in Payara Server#command-execution#java#payaraVulnerability 2 sources
arXiv cs.CR·23d agoAn Empirical Analysis of CodeQL False Positives and Query Refinements for Java Vulnerabilities#codeql#false-positives#javaResearch1
Horizon3.ai·25d ago criticalCVE-2026-81578 + CVE-2026-82078 | PaperCut NG/MF Authentication Bypass and Unsafe Dynamic Class Loading Vulnerabilities#authentication-bypass#cve-2026-81578#cve-2026-82078 in the wild 6 min2
Security Affairs·25d ago highU.S. CISA adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog#cisa#huntress#java in the wild 4 min
Palo Alto Unit 42·Aug 17, 2026 criticalCVE-2022-22965: Spring Core Remote Code Execution Vulnerability Exploited In the Wild (SpringShell) (Updated)#cve-2022-22965#java#rce in the wild 15 min1