Ismalicious CVE-2026-88789: High-Risk XML Vulnerability in Apache Camel Quarkus
Article Content
- •CVE-2026-88789 affects Apache Camel Quarkus versions 3.2.0 to 3.40.0.
- •The vulnerability allows attackers to read local files and access internal networks.
- •A proof-of-concept was published on 2026-10-01, but no active exploitation has been confirmed.
CVE-2026-88789 is a vulnerability in the XSLT support extension of Apache Camel Quarkus, affecting versions from 3.2.0 to 3.40.0. This flaw allows attackers to read local files or access internal network locations by supplying a malicious XML document with external entity declarations. The vulnerability arises from the extension's use of an insecure Xalan-backed TransformerFactory that does not enforce external access restrictions. A proof-of-concept (PoC) for this vulnerability was published on 2026-10-01. The CVSS score for this vulnerability is 8.6, indicating high severity. As of now, active exploitation has not been confirmed, but the potential for exploitation is significant. Users are advised to upgrade to versions 3.33.3 or 3.40.0 or later to mitigate this risk.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-1340 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which versions of Apache Camel Quarkus are affected?
Is there any active exploitation of this vulnerability?
What should users do to protect themselves?
Continue Reading
Citrix NetScaler Critical Vulnerabilities Exploited: Urgent Patching Required Citrix NetScaler ADC and Gateway products are affected by critical vulnerabilities CVE-2026-88771 and CVE-2026-88772, both assigned a CVSS score of 9.5. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on September 27, 2026, and mandated…
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…