AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-71558

CRITICAL · CVSS 9.8 EPSS 0.71% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-07 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

A heap type confusion vulnerability exists in Apache Fory C++ versions 0.14.0 through 1.5.0, where crafted input can bypass type checks during polymorphic smart-pointer deserialization. This flaw may lead to undefined behavior, potentially resulting in denial of service or arbitrary code execution. Organizations utilizing affected versions should prioritize upgrading to Apache Fory 1.5.0 to mitigate these risks, especially if their applications rely on polymorphic smart-pointer deserialization.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
arbitrary code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-71558
Severity
CRITICAL
CVSS
9.8
EPSS
0.71%
Apache

Original NVD Description

Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafted input payload can bypass type compatibility checks during polymorphic smart-pointer deserialization, causing an object of an incompatible type to be treated as the declared base type. This may result in undefined behavior and potentially lead to denial of service or arbitrary code execution. Users are recommended to upgrade to Apache Fory 1.5.0, which fixes this issue. Applications not using Apache Fory C++ polymorphic smart-pointer deserialization are not affected.

Related CVEs

Other vulnerabilities affecting the same vendor(s)