CVE-2026-28672: Apache Ranger
Critical severity, CVSS 9.8. EPSS: 2.6% chance of exploitation in the next 30 days.
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger. This issue affects Apache Ranger: from 0.6 through 2.8.
Affected products
- Apache Ranger: from 0.6.0, up to and including 2.8.0
Published 2026-08-10. Last modified 2026-08-17.