OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-68536

CRITICAL · CVSS 9.8 EPSS 0.49%

Source: NVD + CISA KEV + EPSS · Published 2026-09-16 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

Apache MyFace Core is vulnerable to server-side request forgery and local file inclusion, potentially allowing attackers to manipulate server requests or access sensitive files. Organizations using affected versions, especially those running older unsupported releases, should prioritize upgrading to versions 2.3.12, 2.3-next-M9, 3.0.4, 4.0.4, or 4.1.4 to mitigate these risks.

CVE
CVE-2026-68536
Severity
CRITICAL
CVSS
9.8
EPSS
0.49%
Apache

Original NVD Description

Server-Side Request Forgery / Local File Inclusion in Apache MyFace Core. Older unsupported versions may also be affected.  Users are recommended to upgrade to versions 2.3.12, 2.3-next-M9, 3.0.4, 4.0.4, or 4.1.4, which fix this issue.