Apache · Apache Cxf · CVE-2026-44417
**Name of the Vulnerable Software and Affected Versions**
Apache CXF versions prior to 4.2.1
Apache CXF versions prior to 4.1.6
Apache CXF versions prior to 3.6.11
**Description**
An incomplete fix for a previous issue allows for remote code execution if untrusted users are permitted to configure the Java Message Service (JMS), a Java API that allows applications to create, send, receive, and read messages.
**Recommendations**
Upgrade to version 4.2.1.
Upgrade to version 4.1.6.
Upgrade to version 3.6.11.