Skip to content
THREATWIRE

Index

Search

Search the public record. Drafts and scheduled notes are not included.

High

news

Camel Quarkus XXE is CVE-2026-88789

Apache disclosed CVE-2026-88789 in Camel Quarkus: the Xalan-backed XSLT support factory drops JAXP external-access hardening, enabling XXE that can read local files or reach internal hosts. CVSS 3.1 8.6 from Apache. Fixed in 3.33.3 and 3.40.0. A public reproducer exists. Not in CISA KEV.

Published 1h ago

High

news

Apache Struts 7.4.0 fixes four security flaws

On 5 October 2026 Apache published S2-075 through S2-078 for Struts, covering OGNL injection in the legacy RESTful mapper, BigDecimal response expansion, an unbounded REST body read, and a shared date/time message formatter. Fixes ship in 7.4.0 and 6.12.0. No CVSS scores or CISA KEV listings yet.

Published 3h ago

Critical

news

OpenOffice Java bug has no released fix

CVE-2026-59265 can run code when a person opens a crafted document in Apache OpenOffice 4.1.16 or earlier. There is no CVSS score, no KEV listing, and no finished 4.1.17 release.

Published 5h ago

MediumNo PoC

CVE-2026-104711

OGNL injection in the legacy RESTful action mapper

RCE

Published 19h ago

MediumNo PoC

CVE-2026-104712

Disproportionate BigDecimal response expansion (DoS)

DoS

Published 19h ago

HighNo PoC

CVE-2026-104713

Unbounded REST plugin request body read (DoS)

DoS

Published 19h ago

MediumNo PoC

CVE-2026-104714

Shared message formatter leaks date or time across requests

Info disclosure

Published 19h ago

CriticalNo PoC

CVE-2026-59265

OpenOffice Java document code execution

RCE

Published 3d ago

HighPoC Available

CVE-2026-88789

Camel Quarkus Xalan TransformerFactory drops XXE hardening

Other

Published 4d ago

CriticalActive ExploitationKEV

CVE-2021-44228

Apache Log4j JNDI remote code execution

RCE

Published 10 Dec 2021