CVE-2026-65432 | Apache CXF up to 3.6.11/4.1.7/4.2.2 StaxUtils/WSDL4J xml external entity reference
A vulnerability identified as critical has been detected in Apache CXF up to 3.6.11/4.1.7/4.2.2. This impacts an unknown function of the component StaxUtils/WSDL4J. The manipulation leads to xml external entity reference.
This vulnerability is traded as CVE-2026-65432. It is possible to initiate the attack remotely. There is no exploit available.
You should upgrade the affected component.VulDB Recent EntriesRead More