SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-64606

CRITICAL · CVSS 9.8 EPSS 0.63%

Source: NVD + CISA KEV + EPSS · Published 2026-07-21 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

A critical deserialization vulnerability in Apache Fory allows attackers to bypass class-registration checks during Java lambda deserialization, specifically affecting the lambda capture class. This could lead to unauthorized code execution or data manipulation, posing significant risks to applications utilizing affected versions prior to 1.4.0. Organizations using Apache Fory should prioritize upgrading to version 1.4.0 to mitigate this severe threat.

CVE
CVE-2026-64606
Severity
CRITICAL
CVSS
9.8
EPSS
0.63%
Apache Java

Original NVD Description

Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lambda deserialization. Only lambda capture class is affected This issue affects Apache Fory: from before 1.4.0. Users are recommended to upgrade to version 1.4.0, which fixes the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)