CVE-2026-49875: Apache Cxf
Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.
Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fix this issue.
Affected products
- Apache Cxf: before 4.1.7 (fixed in 4.1.7); from 4.2.0, before 4.2.2 (fixed in 4.2.2)
Published 2026-06-12. Last modified 2026-08-07.