Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4508 articles · 223849 vulns · 37/41 feeds (7d)
← Back to list
9.8
CVE-2026-66713PATCHED
apache · axis2\/java

Apache Axis2/Java: deserialization of untrusted Data

Description

Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component  in Apache Software Foundation Apache Axis2/Java through 2.0.0 on Apache Tomcat  (only when Tribes clustering is enabled, which is off by default) allows an  unauthenticated remote attacker with network access to the clustering port to  execute arbitrary code via a crafted serialized Java object delivered to the cluster  channel and deserialized in  org.apache.axis2.clustering.tribes.Axis2ChannelListener#messageReceived. Users are  recommended to upgrade to version 2.0.1, which fixes this issue by removing the  clustering feature entirely.

Affected Products

VendorProductVersions
apacheaxis2\/java0

References

  • https://github.com/apache/axis-axis2-java-core/commit/e6f53b230bddcb40577c84ff290ba51e7265fa15(patch)
  • https://lists.apache.org/thread/fgggbv3sjjqw7p6q0j88gspt9b2rb728(vendor-advisory)

Related News (4 articles)

Tier B
CERT-FR10d ago
Multiples vulnérabilités dans les produits IBM (18 septembre 2026)
→ No new info (linked only)
Tier C
VulDB61d ago
CVE-2026-66713 | Apache Axis2/Java up to 2.0.0 Tribes-based Clustering deserialization
→ No new info (linked only)
Tier B
BSI Advisories61d ago
[NEU] [hoch] Apache Axis2: Schwachstelle ermöglicht Codeausführung
→ No new info (linked only)
Tier C
oss-security61d ago
CVE-2026-66713: Apache Axis2/Java: deserialization of untrusted Data
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.19.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
https://github.com/apache/axis-axis2-java-core/commit/e6f53b230bddcb40577c84ff290ba51e7265fa15https://lists.apache.org/thread/fgggbv3sjjqw7p6q0j88gspt9b2rb728
CWECWE-502
PublishedJul 28, 2026
Last enriched61d ago
Trending Score20
Source articles4
Independent4
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-71290
Apache HttpComponents Client: TLS hostname verification silently disabled on the async transport (default config, MITM)
Trending: 45
HIGHCVE-2026-59878
Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All: AMQP NIO negative frame size validation bypass leading to DoS
Trending: 38
CRITICALCVE-2026-55976
Apache Hive: SSRF vulnerability in Hive Avro Serde due to Insufficient input validation on avro.schema.url
Trending: 33
CRITICALCVE-2026-49845
Apache Hive: SQL Injection vulnerability in HiveMetaStore partition-name direct-SQL paths
Trending: 27
CRITICALCVE-2026-59083EXP
Apache Tomcat: Incorrect URL decoding in RewriteValve may allow security control bypass
Trending: 19

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 28, 2026
Discovered by ZDM
Jul 28, 2026
Patch Available
Jul 29, 2026