Frequency
2
occurrences
First Seen
January 20, 2026
Last Seen
January 28, 2026
Related Threat Clusters
-
Critical Command Injection Vulnerability in Apache bRPC Identified
CyberArk Labs has discovered a critical command injection vulnerability in Apache bRPC, allowing unauthenticated remote code execution via the exposed /pprof/heap HTTP endpoint. The issue has been assigned…
2 articles · Updated January 28, 2026 -
Critical Apache bRPC Vulnerability Allows Remote Command Injection
A critical remote command-injection vulnerability has been found in Apache bRPC's heap profiler service, affecting all versions prior to 1.15.0 across all platforms. This flaw enables unauthenticated attackers to…
2 articles · Updated January 20, 2026
Recent Intelligence Reports
- Critical flaw in Apache bRPC exposes debug endpoint — Securitybrief.Au · January 28, 2026
- Apache bRPC Vulnerability Enables Remote Command Injection Attacks — Cyberpress · January 20, 2026