Critical 1 vendor · 2 advisories
CVE-2026-59243
CVE-2026-59243: critical-severity vulnerability covered by 2 tracked advisory records across Apache. Compare affected products, fixed versions and remediation.
Android app · Google Play
Monitor future Apache CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Matching phone alertsOptional email delivery
Apache2 advisories
- Critical9.8Critical [CVE-2026-59243] Apache Airflow FAB provider: FAB auth manager: JWT signature verification disabled by default for Azure AD OAuth (`verify_signature` defaults to `False`)Jul 29, 2026
- Critical9.1Critical [CVE-2026-59243 +1] Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the issuer or audience of Azure AD `id_token`s during OAuth loginSep 8, 2026