CVE-2026-68536: Apache Software Foundation Apache Myfaces

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Server-Side Request Forgery / Local File Inclusion in Apache MyFace Core. Older unsupported versions may also be affected.  Users are recommended to upgrade to versions 2.3.12, 2.3-next-M9, 3.0.4, 4.0.4, or 4.1.4, which fix this issue.

Affected products

  • Apache Software Foundation Apache Myfaces: from 2.2.0-beta, up to and including 2.2.15; version 2.3.0 only; from 2.3-next-M1, before 2.3-next-M9 (fixed in 2.3-next-M9); from 2.3.1, before 2.3.12 (fixed in 2.3.12); from 3.0.0, before 3.0.4 (fixed in 3.0.4); from 4.0.0, before 4.0.4 (fixed in 4.0.4); …

Published 2026-09-16. Last modified 2026-09-17.