<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>0dayNews — Apache</title><description>Vulnerabilities in Apache Software Foundation projects — most notably Log4j, the ubiquitous Java logging library whose Log4Shell flaw became one of the most widely exploited vulnerabilities in internet history. Combined article + CVE feed for the Apache beat.</description><link>https://0daynews.com/</link><language>en-us</language><item><title>CVE-2006-1547 — Apache Struts 1 ActionForm Denial-of-Service Vulnerability</title><link>https://0daynews.com/cve/cve-2006-1547/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2006-1547/</guid><description>ActionForm in Apache Struts versions before 1.2.9 with BeanUtils 1.7 contains a vulnerability that allows for denial-of-service (DoS).</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Apache</category><category>high</category><category>cve</category></item><item><title>CVE-2012-0391 — Apache Struts 2 Improper Input Validation Vulnerability</title><link>https://0daynews.com/cve/cve-2012-0391/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2012-0391/</guid><description>The ExceptionDelegator component in Apache Struts 2 before 2.2.3.1 contains an improper input validation vulnerability that allows for remote code execution.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Apache</category><category>critical</category><category>cve</category></item><item><title>CVE-2013-2251 — Apache Struts Improper Input Validation Vulnerability</title><link>https://0daynews.com/cve/cve-2013-2251/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2013-2251/</guid><description>Apache Struts allows remote attackers to execute arbitrary Object-Graph Navigation Language (OGNL) expressions.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Apache</category><category>critical</category><category>cve</category></item><item><title>CVE-2016-3088 — Apache ActiveMQ Improper Input Validation Vulnerability</title><link>https://0daynews.com/cve/cve-2016-3088/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2016-3088/</guid><description>The Fileserver web application in Apache ActiveMQ allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Apache</category><category>critical</category><category>cve</category></item><item><title>CVE-2016-4437 — Apache Shiro Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2016-4437/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2016-4437/</guid><description>Apache Shiro contains a vulnerability which may allow remote attackers to execute code or bypass intended access restrictions via an unspecified request parameter when a cipher key has not been configured for the &quot;remember me&quot; feature.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Apache</category><category>critical</category><category>cve</category></item><item><title>CVE-2016-8735 — Apache Tomcat Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2016-8735/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2016-8735/</guid><description>Apache Tomcat contains an unspecified vulnerability that allows for remote code execution if JmxRemoteLifecycleListener is used and an attacker can reach Java Management Extension (JMX) ports. This CVE exists because this listener wasn&apos;t updated for consistency with the Oracle patched issues for CVE-2016-3427 which affected credential types.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Apache</category><category>critical</category><category>cve</category></item><item><title>CVE-2017-12615 — Apache Tomcat on Windows Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2017-12615/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-12615/</guid><description>When running Apache Tomcat on Windows with HTTP PUTs enabled, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Apache</category><category>high</category><category>cve</category></item><item><title>CVE-2017-12617 — Apache Tomcat Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2017-12617/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-12617/</guid><description>When running Apache Tomcat, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Apache</category><category>high</category><category>cve</category></item><item><title>CVE-2017-5638 — Apache Struts Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2017-5638/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-5638/</guid><description>Apache Struts Jakarta Multipart parser allows for malicious file upload using the Content-Type value, leading to remote code execution.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Apache</category><category>critical</category><category>cve</category></item><item><title>CVE-2017-9791 — Apache Struts 1 Improper Input Validation Vulnerability</title><link>https://0daynews.com/cve/cve-2017-9791/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-9791/</guid><description>The Struts 1 plugin in Apache Struts might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Apache</category><category>critical</category><category>cve</category></item><item><title>CVE-2017-9805 — Apache Struts Deserialization of Untrusted Data Vulnerability</title><link>https://0daynews.com/cve/cve-2017-9805/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-9805/</guid><description>Apache Struts REST Plugin uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to remote code execution when deserializing XML payloads.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Apache</category><category>high</category><category>cve</category></item><item><title>CVE-2018-11776 — Apache Struts Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2018-11776/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2018-11776/</guid><description>Apache Struts contains a vulnerability that allows for remote code execution under two circumstances. One, where the alwaysSelectFullNamespace option is true and the value isn&apos;t set for a result defined in underlying configurations and in same time, its upper package configuration have no or wildcard namespace.  Or, using URL tag which doesn&apos;t have value and action set and in same time, its upper package configuration have no or wildcard namespace.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Apache</category><category>high</category><category>cve</category></item><item><title>CVE-2019-0193 — Apache Solr DataImportHandler Code Injection Vulnerability</title><link>https://0daynews.com/cve/cve-2019-0193/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-0193/</guid><description>The optional Apache Solr module DataImportHandler contains a code injection vulnerability.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Apache</category><category>high</category><category>cve</category></item><item><title>CVE-2019-0211 — Apache HTTP Server Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2019-0211/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-0211/</guid><description>Apache HTTP Server, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute code with the privileges of the parent process (usually root) by manipulating the scoreboard.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Apache</category><category>high</category><category>cve</category></item><item><title>CVE-2019-17558 — Apache Solr VelocityResponseWriter Plug-In Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2019-17558/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-17558/</guid><description>The Apache Solr VelocityResponseWriter plug-in contains an unspecified vulnerability which can allow for remote code execution.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Apache</category><category>high</category><category>cve</category></item><item><title>CVE-2020-11978 — Apache Airflow Command Injection</title><link>https://0daynews.com/cve/cve-2020-11978/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-11978/</guid><description>A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Apache</category><category>high</category><category>cve</category></item><item><title>CVE-2020-13927 — Apache Airflow&apos;s Experimental API Authentication Bypass</title><link>https://0daynews.com/cve/cve-2020-13927/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-13927/</guid><description>The previous default setting for Airflow&apos;s Experimental API was to allow all API requests without authentication.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Apache</category><category>critical</category><category>cve</category></item><item><title>CVE-2020-17519 — Apache Flink Improper Access Control Vulnerability</title><link>https://0daynews.com/cve/cve-2020-17519/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-17519/</guid><description>Apache Flink contains an improper access control vulnerability that allows an attacker to read any file on the local filesystem of the JobManager through its REST interface.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Apache</category><category>high</category><category>cve</category></item><item><title>CVE-2020-17530 — Apache Struts Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2020-17530/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-17530/</guid><description>Forced Object-Graph Navigation Language (OGNL) evaluation in Apache Struts, when evaluated on raw user input in tag attributes, can lead to remote code execution.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Apache</category><category>critical</category><category>cve</category></item><item><title>CVE-2020-1938 — Apache Tomcat Improper Privilege Management Vulnerability</title><link>https://0daynews.com/cve/cve-2020-1938/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-1938/</guid><description>Apache Tomcat treats Apache JServ Protocol (AJP) connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Apache</category><category>critical</category><category>cve</category></item><item><title>CVE-2020-1956 — Apache Kylin OS Command Injection Vulnerability</title><link>https://0daynews.com/cve/cve-2020-1956/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-1956/</guid><description>Apache Kylin contains an OS command injection vulnerability which could permit an attacker to perform remote code execution.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Apache</category><category>high</category><category>cve</category></item><item><title>CVE-2021-40438 — Apache HTTP Server-Side Request Forgery (SSRF)</title><link>https://0daynews.com/cve/cve-2021-40438/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-40438/</guid><description>A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Apache</category><category>critical</category><category>cve</category></item><item><title>CVE-2021-41773 — Apache HTTP Server Path Traversal Vulnerability</title><link>https://0daynews.com/cve/cve-2021-41773/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-41773/</guid><description>Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default �require all denied� or if CGI scripts are enabled. The original patch issued under this CVE ID is insufficient, please review remediation information under CVE-2021-42013.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Apache</category><category>critical</category><category>cve</category></item><item><title>CVE-2021-42013 — Apache HTTP Server Path Traversal Vulnerability</title><link>https://0daynews.com/cve/cve-2021-42013/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-42013/</guid><description>Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default require all denied or if CGI scripts are enabled. This CVE ID resolves an incomplete patch for CVE-2021-41773.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Apache</category><category>critical</category><category>cve</category></item><item><title>CVE-2021-44228 — Log4Shell — Apache Log4j2 Remote Code Execution</title><link>https://0daynews.com/cve/cve-2021-44228/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-44228/</guid><description>A critical remote-code-execution vulnerability in Apache Log4j2, the ubiquitous Java logging library, allows an unauthenticated attacker to execute arbitrary code simply by getting a string they control logged — via JNDI lookup injection. One of the most widely exploited vulnerabilities in internet history due to Log4j&apos;s near-universal presence in Java applications.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Apache</category><category>critical</category><category>cve</category></item><item><title>CVE-2021-45046 — Apache Log4j2 Deserialization of Untrusted Data Vulnerability</title><link>https://0daynews.com/cve/cve-2021-45046/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-45046/</guid><description>Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Apache</category><category>critical</category><category>cve</category></item><item><title>CVE-2022-24112 — Apache APISIX Authentication Bypass Vulnerability</title><link>https://0daynews.com/cve/cve-2022-24112/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2022-24112/</guid><description>Apache APISIX contains an authentication bypass vulnerability that allows for remote code execution.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Apache</category><category>critical</category><category>cve</category></item><item><title>CVE-2022-24706 — Apache CouchDB Insecure Default Initialization of Resource Vulnerability</title><link>https://0daynews.com/cve/cve-2022-24706/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2022-24706/</guid><description>Apache CouchDB contains an insecure default initialization of resource vulnerability which can allow an attacker to escalate to administrative privileges.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Apache</category><category>critical</category><category>cve</category></item><item><title>CVE-2022-33891 — Apache Spark Command Injection Vulnerability</title><link>https://0daynews.com/cve/cve-2022-33891/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2022-33891/</guid><description>Apache Spark contains a command injection vulnerability via Spark User Interface (UI) when Access Control Lists (ACLs) are enabled.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Apache</category><category>high</category><category>cve</category></item><item><title>CVE-2023-27524 — Apache Superset Insecure Default Initialization of Resource Vulnerability</title><link>https://0daynews.com/cve/cve-2023-27524/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2023-27524/</guid><description>Apache Superset contains an insecure default initialization of a resource vulnerability that allows an attacker to authenticate and access unauthorized resources on installations that have not altered the default configured SECRET_KEY according to installation instructions.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Apache</category><category>high</category><category>cve</category></item><item><title>CVE-2023-33246 — Apache RocketMQ Command Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2023-33246/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2023-33246/</guid><description>Several components of Apache RocketMQ, including NameServer, Broker, and Controller, are exposed to the extranet and lack permission verification. An attacker can exploit this vulnerability by using the update configuration function to execute commands as the system users that RocketMQ is running as or achieve the same effect by forging the RocketMQ protocol content.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Apache</category><category>critical</category><category>cve</category></item><item><title>CVE-2023-46604 — Apache ActiveMQ Deserialization of Untrusted Data Vulnerability</title><link>https://0daynews.com/cve/cve-2023-46604/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2023-46604/</guid><description>Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow a remote attacker with network access to a broker to run shell commands by manipulating serialized class types in the OpenWire protocol to cause the broker to instantiate any class on the classpath.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Apache</category><category>critical</category><category>cve</category></item><item><title>CVE-2024-27348 — Apache HugeGraph-Server Improper Access Control Vulnerability</title><link>https://0daynews.com/cve/cve-2024-27348/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-27348/</guid><description>Apache HugeGraph-Server contains an improper access control vulnerability that could allow a remote attacker to execute arbitrary code.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Apache</category><category>critical</category><category>cve</category></item><item><title>CVE-2024-32113 — Apache OFBiz Path Traversal Vulnerability</title><link>https://0daynews.com/cve/cve-2024-32113/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-32113/</guid><description>Apache OFBiz contains a path traversal vulnerability that could allow for remote code execution.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Apache</category><category>critical</category><category>cve</category></item><item><title>CVE-2024-38475 — Apache HTTP Server Improper Escaping of Output Vulnerability</title><link>https://0daynews.com/cve/cve-2024-38475/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-38475/</guid><description>Apache HTTP Server contains an improper escaping of output vulnerability in mod_rewrite that allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Apache</category><category>critical</category><category>cve</category></item><item><title>CVE-2024-38856 — Apache OFBiz Incorrect Authorization Vulnerability</title><link>https://0daynews.com/cve/cve-2024-38856/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-38856/</guid><description>Apache OFBiz contains an incorrect authorization vulnerability that could allow remote code execution via a Groovy payload in the context of the OFBiz user process by an unauthenticated attacker.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Apache</category><category>critical</category><category>cve</category></item><item><title>CVE-2024-45195 — Apache OFBiz Forced Browsing Vulnerability</title><link>https://0daynews.com/cve/cve-2024-45195/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-45195/</guid><description>Apache OFBiz contains a forced browsing vulnerability that allows a remote attacker to obtain unauthorized access.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Apache</category><category>high</category><category>cve</category></item><item><title>CVE-2025-24813 — Apache Tomcat Path Equivalence Vulnerability</title><link>https://0daynews.com/cve/cve-2025-24813/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-24813/</guid><description>Apache Tomcat contains a path equivalence vulnerability that allows a remote attacker to execute code, disclose information, or inject malicious content via a partial PUT request.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Apache</category><category>critical</category><category>cve</category></item><item><title>CVE-2026-34197 — Apache ActiveMQ Improper Input Validation Vulnerability</title><link>https://0daynews.com/cve/cve-2026-34197/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-34197/</guid><description>Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Apache</category><category>high</category><category>cve</category></item><item><title>CVE-2026-34486 — Apache Tomcat Missing Encryption of Sensitive Data Vulnerability</title><link>https://0daynews.com/cve/cve-2026-34486/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-34486/</guid><description>Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Apache</category><category>high</category><category>cve</category></item><item><title>Apache Tomcat EncryptInterceptor Bypass Added to KEV — Patch by Aug 7</title><link>https://0daynews.com/articles/2026-08-06-apache-tomcat-cve-2026-34486-encryptinterceptor-kev/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-06-apache-tomcat-cve-2026-34486-encryptinterceptor-kev/</guid><description>CVE-2026-34486 lets attackers bypass Tomcat&apos;s EncryptInterceptor, exposing clustered node traffic. CISA added it to KEV on Aug 4 after active exploitation. Fixed builds are out.</description><pubDate>Thu, 06 Aug 2026 20:40:00 GMT</pubDate><category>Apache</category><category>article</category></item><item><title>Log4Shell, Explained: The Internet&apos;s Worst Week</title><link>https://0daynews.com/articles/2026-06-30-log4shell-log4j-anniversary-explainer/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-06-30-log4shell-log4j-anniversary-explainer/</guid><description>CVE-2021-44228 turned a single misused feature in Apache Log4j2 — a Java logging library embedded almost everywhere — into one of the most widely exploited vulnerabilities ever recorded.</description><pubDate>Tue, 30 Jun 2026 13:00:00 GMT</pubDate><category>Apache</category><category>article</category></item></channel></rss>