Securitybrief.Au
Critical Command Injection Vulnerability in Apache bRPC Identified
First seen 29 Jan 2026, 22:53 UTC
•
•38.8
Export
Article Content
Browse articles
CyberArk Labs has discovered a critical command injection vulnerability in Apache bRPC, allowing unauthenticated remote code execution via the exposed /pprof/heap HTTP endpoint. The issue has been assigned CVE-2025-60021 by Apache with a CVSS score of 9.8, attributed to researcher Simon Kosman.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
FortiWeb WAF Vulnerability Enables Full Admin Control Exploitation
CISA Warns of Critical Exploits in Langflow, Tomcat, and N-central Flaws
Critical Oracle WebLogic Flaw Under Active Exploitation
FamousSparrow APT Expands Targeting to Azerbaijani Energy Sector
Critical Apache HTTP Server Vulnerability Poses Remote Code Execution Risk
Critical RCE Vulnerability in Windchill and FlexPLM Triggers Urgent Alerts