Frequency
1
occurrences
First Seen
February 3, 2026
Last Seen
February 3, 2026
Exploited in Wild
—
Ransomware Use
—
Public Exploits
—
Attack Vector
—
Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
A critical XML External Entity (XXE) vulnerability, tracked as CVE-2026-23795, has been disclosed in the Apache Syncope identity management console. This flaw can allow attackers to hijack active user sessions and expose sensitive user data. Multiple versions of the platform are affected and require...
Public Exploits
Checking GitHub for proof-of-concept code…