CVE-2026-66909Apache · Cxf
Vulnerability data via NVD (ingested)
Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place. Any attacker able to place a message on the service's JMS destination can submit a malicious serialized object, leading to denial of service or, if a suitable gadget class is on the classpath, remote code execution. The fix disables ObjectMessage deserialization by default, with a configuration switch to re-enable it if needed. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-66909product:"Apache Cxf"http.html:"Cxf"More intel sources (5)
vuln:CVE-2026-66909vulnerabilities.cve_id: CVE-2026-66909CVE-2026-66909CVE-2026-66909"CVE-2026-66909" exploit -site:nvd.nist.gov