A vulnerability, which was classified as problematic, was found in Apache CXF up to 3.6.12/4.1.8/4.2.3. This affects the function STSTokenValidator. The manipulation results in information disclosure. This vulnerability is known as CVE-2026-97791. It is possible to launch the attack remotely. No exploit is available. You should upgrade the... Weiterlesen: CVE-2026-97791 | Apache CXF up to 3.6.12/4.1.8/4.2.3 STSTokenValidato…
Intelligence View
⚡ tsecurity.de Intelligence
CVE-2026-97791 | Apache CXF up to 3.6.12/4.1.8/4.2.3 STSTokenValidator information disclosure (WID-SEC-2026-3824)
A vulnerability, which was classified as problematic, was found in Apache CXF up to 3.6.12/4.1.8/4.2.3. This affects the function STSTokenValidator. The…
Cyber Threat Intelligence & Forensik
ATT&CK-Navigator · IoC-Radar · Exploit-Belege
Compliance, SLA & Vendor Adherence
Advisory-Prüfung · Score-Einordnung · Fristen
BSI-Warnung (Deutschland)CVE-2026-97791
Apache CXF: Mehrere Schwachstellen hoch08.10.2026
Advisory Radar
Offizielles Hersteller-Update verfügbar
Hersteller-Sicherheitsmeldungen & Patch-Status
Handlungsempfehlung für Administratoren
Hersteller hat ein verifiziertes Patch-Release herausgegeben. Sofortiges Rollout auf Test- und Produktivsystemen empfohlen.
Referenzen aus der Primärquelle („Verifiziert" nur bei Hersteller-Domäne):
-
Apache Security Advisory Verifiziertapache.org
Intelligence Digest — kostenlos Täglich die wichtigsten Security-News · jederzeit abbestellbar
Diese Meldung in anderen Quellen
+5