CVE-2015-8765: McAfee Epolicy Orchestrator

High severity, CVSS 8.3. EPSS: 2.7% chance of exploitation in the next 30 days.

Intel McAfee ePolicy Orchestrator (ePO) 4.6.9 and earlier, 5.0.x, 5.1.x before 5.1.3 Hotfix 1106041, and 5.3.x before 5.3.1 Hotfix 1106041 allow remote attackers to execute arbitrary code via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.

Affected products

  • McAfee Epolicy Orchestrator: up to and including 4.6.9; from 5.0.0, up to and including 5.0.1; from 5.1.0, before 5.1.3 (fixed in 5.1.3); from 5.3.0, before 5.3.1 (fixed in 5.3.1)

Published 2016-01-08. Last modified 2026-06-17.