CVE-2026-66909
CVE-2026-66909: 3 tracked advisory records across Apache, NetApp, Red Hat. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Apache
1 advisory- Advisory severityCritical9.8
Critical [CVE-2026-66909] Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place
CVE-2026-66909Source published Source updated
Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place. Any attacker able to place a message on the service's JMS destination can submit a malicious serialized object, leading to denial of service or, if a suitable gadget class is on the classpath, remote code execution. The fix disables ObjectMessage deserialization by default, with a configuration switch to re-enable it if needed. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
- Affected products in this advisory
- Apache CXF
- Source-reported affected versions
- Apache CXF 4.2.0 before 4.2.3
- Apache CXF 4.0.0 before 4.1.8
- Apache CXF before 3.6.12
- Source-reported fixed versions
- 4.2.3
- 4.1.8
- 3.6.12
- Mitigation guidance
- The fix disables ObjectMessage deserialization by default, with a configuration switch to re-enable it if needed.
- Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
NetApp
1 advisory- Advisory severityCritical9.8
Critical [CVE-2026-66909] Apache CXF Vulnerability in NetApp Products
NTAP-20260911-0001Source published Source updated
Apache CXF versions prior to 3.6.12, 4.0.0 prior to 4.1.8, and 4.2.0 prior to 4.2.3 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
- Affected products in this advisory
- No product details extracted. Check the source bulletin.
- Source-reported affected versions
- 3.6.12
- 4.0.0
- 4.1.8
- 4.2.0
1 more entries in the full advisory.
- Source-reported fixed versions
- No fixed-version detail extracted. This does not mean no fix exists.
- Mitigation guidance
- No mitigation guidance extracted; consult the source.
Red Hat
1 advisory- Advisory severityHigh8.1
High [CVE-2026-66909] Remote Code Execution via unsafe deserialization of JMS ObjectMessage
CVE-2026-66909Source published Source updated
Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place. Any attacker able to place a message on the service's JMS destination can submit a malicious serialized object, leading to denial of service or, if a suitable gadget class is on the classpath, remote code execution. The fix disables ObjectMessage deserialization by default, with a configuration switch to re-enable it if needed. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue. The Java Message Service (JMS) transport component improperly deserializes inbound JMS ObjectMessages without type restrictions. This vulnerability could lead to a denial of service or, in certain configurations, enable…
- Affected products in this advisory
- Red Hat build of Apache Camel for Spring Boot 4
- Red Hat JBoss Enterprise Application Platform 7
- Red Hat JBoss Enterprise Application Platform 8
- Red Hat JBoss Enterprise Application Platform Expansion Pack
1 more entries in the full advisory.
- Source-reported affected versions
- Affected-version details not available in this record.
- Source-reported fixed versions
- 4.2.3
- 4.1.8
- 3.6.12
- Mitigation guidance
- To mitigate this vulnerability, disable ObjectMessage deserialization in Apache CXF's JMS transport. This can typically be achieved through a configuration setting provided by the Apache CXF framework. Consult the Apache CXF documentation for specific instructions on how to disable ObjectMessage deserialization in your deployment. Disabling this feature may impact applications that rely on ObjectMessage for legitimate data transfer.
Android app · Google Play
Turn CVE research into alerts on your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.