CVE-2025-59059Patch(apache / ranger)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache ranger systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions <= 2.7.0. Users are recommended to upgrade to version 2.8.0, which fixes this issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ranger

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 7 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 6 mentions (2026-03-03); latest day: 1
  • 8 total mentions across 3 days

Affected systems

Vendors
Products
ranger

Deep dive

Activity timeline8 mentions / 3d
02356Mentions · 2026-03-03: 6Mentions · 2026-03-04: 1Mentions · 2026-03-08: 1Patch / Workaround · 2026-03-03: 5Patch / Workaround · 2026-03-04: 1Technical Details · 2026-03-03: 5Technical Details · 2026-03-04: 1Technical Details · 2026-03-08: 103-0303-0403-08
Signal classification3 categories
Patch
562.5%
General
225.0%
Disclosure
112.5%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-036
General1Patch5
2026-03-041
Disclosure1
2026-03-081
General1
Full discourse8 posts
  • Open Source Security mailing list@oss_security
    General

    CVE-2025-59060: Apache Ranger: Hostname verification bypass in NiFiRegistryClient and NifiClient https://www.openwall.com/lists/oss-security/2026/03/02/4 CVE-2025-59059: Apache Ranger: Remote Code Execution Vulnerability in NashornScriptEngineCreator https://www.openwall.com/lists/oss-security/2026/03/02/5 Both are "Severity: low"

    Post summary

    Apache Ranger hosts two low‑severity issues: a hostname verification bypass in NiFiRegistryClient/NifiClient and a remote code execution in NashornScriptEngineCreator; no POC, exploit, patch, or active use details are provided.

    00052632
    4.4K followersView on X
  • CCB Alert@CCBalert
    Disclosure

    Warning: Critical vulnerability in #Apache #Ranger. CVE-2025-59059 CVSS: 9.8. An unauthenticated remote attacker could exploit it to achieve remote code execution! #RCE #Patch #Patch #Patch

    Post summary

    This message announces the CVE‑2025‑59059 critical vulnerability in Apache Ranger, highlighting its remote code execution risk, CVSS score of 9.8, and urging users to apply the patch.

    02000366
    7.2K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2025-59059 Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions &lt;= 2.7.0. Users are recommended to upgrade to version 2.8.0, w… https://www.cve.org/CVERecord?id=CVE-2025-59059

    Post summary

    Apache Ranger versions <=2.7.0 are vulnerable to a remote code execution flaw; users should upgrade to 2.8.0 to remediate.

    00010486
    56.6K followersView on X
  • The Hacker Wire@TheHackerWire
    Patch

    🔴 CVE-2025-59059 - Critical Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions &amp;lt;= 2.7.0. Users are recommended to upgrade to version 2.8.0, which fixes this is... https://www.thehackerwire.com/vulnerability/CVE-2025-59059/ https://t.co/I4QyDThGOr

    Post summary

    The post announces a critical RCE vulnerability in Apache Ranger’s NashornScriptEngineCreator and advises users to upgrade to version 2.8.0 to remediate the issue.

    0000094
    121 followersView on X
  • The Hacker Wire@TheHackerWire
    Patch

    🔴 CVE-2025-59059 - Critical Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions &amp;lt;= 2.7.0. Users are recommended to upgrade to version 2.8.0, which fixes this is... https://www.thehackerwire.com/vulnerability/CVE-2025-59059/ https://t.co/rBTAygaU2L

    Post summary

    The post announces a critical RCE vulnerability in Apache Ranger’s NashornScriptEngineCreator and advises users to upgrade to version 2.8.0 to remediate the issue.

    0000090
    121 followersView on X
  • The Hacker Wire@TheHackerWire
    Patch

    🔴 CVE-2025-59059 - Critical Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions &amp;lt;= 2.7.0. Users are recommended to upgrade to version 2.8.0, which fixes this is... https://www.thehackerwire.com/vulnerability/CVE-2025-59059/ https://t.co/wWOezypHQG

    Post summary

    The post announces a critical RCE vulnerability in Apache Ranger’s NashornScriptEngineCreator and advises users to upgrade to version 2.8.0 to remediate the issue.

    0000087
    121 followersView on X
  • Infoflowcloud@infoflowcloud
    Patch

    🚨*CVE* CVE-2025-59059 Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions &lt;= 2.7.0. Users are recommended to upgrade to version 2.8.0, w… https://www.cve.org/CVERecord?id=CVE-2025-59059 ----- Traducción: CVE-2025-59059 Vul… http://infoflow.cloud`

    Post summary

    Apache Ranger versions up to 2.7.0 contain a remote code execution flaw in NashornScriptEngineCreator; users are advised to upgrade to 2.8.0 to remediate the issue.

    0000082
    55 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2025-59059 CVE-2025-59059 https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-59059

    Post summary

    The text only lists the CVE ID and a link to a vulnerability details page, with no additional information.

    0000077
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheranger---

Explore more