Red Hat JBoss Web Server

2 known vulnerabilities in Red Hat JBoss Web Server, 1 critical, 1 actively exploited, with patch priority, exploit likelihood and the news covering them.

Recently exploited

  • CVE-2026-34486 CVSS 7.5 high · actively exploited Apache Tomcat Missing Encryption of Sensitive Data Vulnerability

Latest vulnerabilities

  • CVE-2026-49875 CVSS 9.8 critical Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening…
  • CVE-2026-34486 CVSS 7.5 high · actively exploited Apache Tomcat Missing Encryption of Sensitive Data Vulnerability