Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5423 articles · 221078 vulns · 37/41 feeds (7d)
← Back to list
9.8
CVE-2026-66713PATCHED
apache · axis2\/java

Apache Axis2/Java: deserialization of untrusted Data

Description

Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component  in Apache Software Foundation Apache Axis2/Java through 2.0.0 on Apache Tomcat  (only when Tribes clustering is enabled, which is off by default) allows an  unauthenticated remote attacker with network access to the clustering port to  execute arbitrary code via a crafted serialized Java object delivered to the cluster  channel and deserialized in  org.apache.axis2.clustering.tribes.Axis2ChannelListener#messageReceived. Users are  recommended to upgrade to version 2.0.1, which fixes this issue by removing the  clustering feature entirely.

Affected Products

VendorProductVersions
apacheaxis2\/java0

References

  • https://github.com/apache/axis-axis2-java-core/commit/e6f53b230bddcb40577c84ff290ba51e7265fa15(patch)
  • https://lists.apache.org/thread/fgggbv3sjjqw7p6q0j88gspt9b2rb728(vendor-advisory)

Related News (4 articles)

Tier B
CERT-FR4d ago
Multiples vulnérabilités dans les produits IBM (18 septembre 2026)
→ No new info (linked only)
Tier C
VulDB56d ago
CVE-2026-66713 | Apache Axis2/Java up to 2.0.0 Tribes-based Clustering deserialization
→ No new info (linked only)
Tier B
BSI Advisories56d ago
[NEU] [hoch] Apache Axis2: Schwachstelle ermöglicht Codeausführung
→ No new info (linked only)
Tier C
oss-security56d ago
CVE-2026-66713: Apache Axis2/Java: deserialization of untrusted Data
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.19.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
https://github.com/apache/axis-axis2-java-core/commit/e6f53b230bddcb40577c84ff290ba51e7265fa15https://lists.apache.org/thread/fgggbv3sjjqw7p6q0j88gspt9b2rb728
CWECWE-502
PublishedJul 28, 2026
Last enriched56d ago
Trending Score37
Source articles4
Independent4
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-59084EXP
Apache Tomcat: EncryptInterceptor requirements not clearly documented
Trending: 42
CRITICALCVE-2026-59083EXP
Apache Tomcat: Incorrect URL decoding in RewriteValve may allow security control bypass
Trending: 42
HIGHCVE-2026-64958
Apache CXF: Denial of service via message header attachments
Trending: 34
HIGHCVE-2026-57819
Apache CXF: No default restriction on the amount of form parameters per message
Trending: 34
HIGHCVE-2026-54225
Apache CXF: Denial of Service attack via large attachments
Trending: 34

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 28, 2026
Discovered by ZDM
Jul 28, 2026
Patch Available
Jul 29, 2026