Apache Software Foundation vendor intelligence

Apache Software Foundation Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting Apache Software Foundation products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

Total KEVs
51
Known exploited vulnerabilities affecting Apache Software Foundation products
In CISA KEV
30
Records also listed in the official catalog
Beyond CISA KEV
21
Additional exploited CVEs absent from CISA KEV
Sensor Observed
5
Apache Software Foundation KEVs with sensor-observed exploitation activity

The catalog gap matters for Apache Software Foundation exposure

21 of the 51 exploited Apache Software Foundation CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 41% of this vendor portfolio.

59%
Covered by CISA
41%
Beyond CISA
26
Product families

Attested Apache Software Foundation CVEs

Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2026-34486

Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor

Apache Tomcat Confirmed In CISA 04 Aug 2026
CVE-2025-68493

Apache Struts, Apache Struts: XXE vulnerability in outdated XWork component

Apache Struts High Beyond CISA 20 Jul 2026
CVE-2021-30128

Unsafe deserialization in Apache OFBiz

Apache OFBiz Confirmed Beyond CISA 12 Jun 2026
CVE-2021-31805

Forced OGNL evaluation, when evaluated on raw not validated user input in tag attributes, may lead to RCE.

Apache Struts Confirmed Beyond CISA 12 Jun 2026
CVE-2020-17518

Apache Flink directory traversal attack: remote file writing through the REST API

Apache Flink Confirmed Beyond CISA 05 Dec 2025
CVE-2023-50968

Apache OFBiz: Arbitrary file properties reading and SSRF attack

Apache OFBiz High Beyond CISA 25 Nov 2025
CVE-2021-37580

Apache ShenYu Admin bypass JWT authentication

Apache ShenYu Admin High Beyond CISA 08 Nov 2025
CVE-2023-49070

Pre-auth RCE in Apache Ofbiz 18.12.09 due to XML-RPC still present

Apache OFBiz High Beyond CISA 07 Jul 2025
CVE-2023-51467

Apache OFBiz: Pre-authentication Remote Code Execution (RCE) vulnerability

Apache OFBiz High Beyond CISA 30 Jun 2025
CVE-2018-1335

From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the...

Apache Tika High Beyond CISA 05 Jul 2025
CVE-2024-45507

Apache OFBiz: Prevent use of URLs in files when loading them from Java or Groovy, leading to a RCE

Apache OFBiz High Beyond CISA 26 Jun 2025
CVE-2020-13942

Remote Code Execution in Apache Unomi

Apache Unomi High Beyond CISA 09 Jun 2025
CVE-2023-47248

PyArrow, PyArrow: Arbitrary code execution when loading a malicious data file

PyArrow High Beyond CISA 09 Jun 2025
CVE-2026-34197

Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans

Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ Confirmed In CISA 01 Jun 2026
CVE-2022-42889

Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults

Apache Commons Text High Beyond CISA 20 Oct 2022
CVE-2024-38475

Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.

Apache HTTP Server Confirmed In CISA 01 May 2025
CVE-2018-11759

The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK...

Apache Tomcat Connectors High Beyond CISA 24 Apr 2025
CVE-2017-12635

Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB before 1.7.0 and 2.x before...

Apache CouchDB High Beyond CISA 25 Apr 2025
CVE-2021-26295

RCE vulnerability in latest Apache OFBiz due to Java serialisation using RMI

Apache OFBiz High Beyond CISA 28 Apr 2025
CVE-2021-27850

Bypass of the fix for CVE-2019-0195

Apache Tapestry High Beyond CISA 28 Apr 2025
CVE-2021-25646

Authenticated users can override system configurations in their requests which allows them to execute arbitrary code.

Apache Druid High Beyond CISA 28 Apr 2025
CVE-2018-11776

Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by...

Apache Struts Confirmed In CISA 03 Nov 2021
CVE-2017-5638

The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message...

Apache Struts Confirmed In CISA 03 Nov 2021
CVE-2020-17530

Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts...

Apache Struts Confirmed In CISA 03 Nov 2021
CVE-2021-41773

Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49

Apache HTTP Server Confirmed In CISA 03 Nov 2021
CVE-2021-42013

Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)

Apache HTTP Server Confirmed In CISA 03 Nov 2021
CVE-2017-9805

The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for...

Apache Struts Confirmed In CISA 03 Nov 2021
CVE-2021-40438

mod_proxy SSRF

Apache HTTP Server Confirmed In CISA 01 Dec 2021
CVE-2021-44228

Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints

Apache Log4j2 Confirmed In CISA 10 Dec 2021
CVE-2020-11978

An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the example...

Apache Airflow Confirmed In CISA 18 Jan 2022
CVE-2006-1547

ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a...

Struts Confirmed In CISA 21 Jan 2022
CVE-2017-9791

The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the...

Apache Struts Confirmed In CISA 10 Feb 2022
CVE-2017-12615

When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default...

Apache Tomcat Confirmed In CISA 25 Mar 2022
CVE-2017-12617

When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via...

Apache Tomcat Confirmed In CISA 25 Mar 2022
CVE-2022-24112

apisix/batch-requests plugin allows overwriting the X-REAL-IP header

Apache APISIX Confirmed In CISA 25 Aug 2022
CVE-2022-24706

Remote Code Execution Vulnerability in Packaging

Apache CouchDB Confirmed In CISA 25 Aug 2022
CVE-2022-33891

Apache Spark shell command injection vulnerability via Spark UI

Apache Spark Confirmed In CISA 07 Mar 2023
CVE-2021-45046

Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack

Apache Log4j Confirmed In CISA 01 May 2023
CVE-2016-8735

Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before...

Apache Tomcat Confirmed In CISA 12 May 2023
CVE-2023-33246

Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function

Apache RocketMQ Confirmed In CISA 06 Sep 2023
CVE-2023-46604

Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack

Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module Confirmed In CISA 02 Nov 2023
CVE-2023-27524

Apache Superset: Session validation vulnerability when using provided default SECRET_KEY

Apache Superset Confirmed In CISA 08 Jan 2024
CVE-2020-17519

Apache Flink directory traversal attack: reading remote files through the REST API

Apache Flink Confirmed In CISA 23 May 2024
CVE-2024-32113

Apache OFBiz: Path traversal leading to RCE

Apache OFBiz Confirmed In CISA 07 Aug 2024
CVE-2024-38856

Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code

Apache OFBiz Confirmed In CISA 27 Aug 2024
CVE-2024-27348

Apache HugeGraph-Server: Command execution in gremlin

Apache HugeGraph-Server Confirmed In CISA 18 Sep 2024
CVE-2024-45195

Apache OFBiz: Confused controller-view authorization logic (forced browsing)

Apache OFBiz Confirmed In CISA 04 Feb 2025
CVE-2025-24813

Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT

Apache Tomcat Confirmed In CISA 01 Apr 2025
CVE-2024-53677

Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks

Apache Struts High Beyond CISA 11 Dec 2024
CVE-2022-24288

Apache Airflow: RCE in example DAGs

Apache Airflow High Beyond CISA 25 Feb 2022
CVE-2018-8006

An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the queue.jsp page of...

Apache ActiveMQ High Beyond CISA 10 Oct 2018

Showing 51 of 51 Apache Software Foundation known exploited vulnerabilities.

Recurring weakness patterns

Deserialization, limitation, and control account for eighteen mapped occurrences across this Apache Software Foundation KEV portfolio.

Browse all KEVs →

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.