Red Hat JBoss Enterprise Application Platform Expansion Pack
12 known vulnerabilities in Red Hat JBoss Enterprise Application Platform Expansion Pack, 2 critical, 1 actively exploited, with patch priority, exploit…
Recently exploited
- CVE-2026-34197 CVSS 8.8 high · actively exploited Apache ActiveMQ Improper Input Validation Vulnerability
Latest vulnerabilities
- CVE-2026-85511 CVSS 4.2 medium A flaw was found in EAP's Elytron. An EAP application whose security domain is backed by an Elytron token-realm with oauth2-introspection…
- CVE-2026-81829 CVSS 5.3 medium A flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is used by applications to verify JSON Web Tokens signed by AWS Application…
- CVE-2026-17526 CVSS 7.2 high Keycloak is an open-source identity and access management solution. A vulnerability was discovered where a user with the impersonation…
- CVE-2026-18212 CVSS 7.5 high A flaw was found in the SAML Redirect Binding implementation of Keycloak, an open-source identity and access management solution. The…
- CVE-2026-17615 CVSS 7.5 high A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker to perform an unauthenticated remote…
- CVE-2026-12894 CVSS 8.8 high A flaw was found in the Qute template engine, which is used by Quarkus to generate dynamic content like HTML pages or emails. The issue…
- CVE-2026-81624 CVSS 7.5 high Undertow is a flexible performant web server used in JBoss EAP and WildFly. A flaw was found in how Undertow handles WebSocket…
- CVE-2026-5680 CVSS 7.5 high A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending specially crafted WebSocket messages with…
- CVE-2026-18963 CVSS 9.1 critical A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access…
- CVE-2026-49875 CVSS 9.8 critical Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening…
- CVE-2026-39364 CVSS 8.2 high Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be…
- CVE-2026-34197 CVSS 8.8 high · actively exploited Apache ActiveMQ Improper Input Validation Vulnerability