CVE-2026-103877

LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Deserialization of Untrusted Data vulnerability in Apache Directory LDAP API. A rogue/compromised LDAP server (or pre-TLS MITM) can answer a client's loadSchema() subschema search with a schema object that contains a serialized Java class, allowing some potential RCE.  This issue affects Apache Directory LDAP API: from 2.1.0 before 2.1.9. Users are recommended to upgrade to version 2.1.9, which fixes the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-04: 110-04
Referenced assets1 URL
By indicator
Full discourse1 post
  • zoomeyebot@zoomeyebot

    🚨 Apache Directory LDAP API Deserialization Flaw (CVE-2026-103877) Enables Remote Code Execution Critical Vulnerability Alert! Apache Directory LDAP API is affected by CVE-2026-103877. 🔍 Identify Targets via ZoomEye: Search Dork: app="ApacheDS" Exposure: 154 instances identified globally. ZoomEye Search Link: 👉 https://www.zoomeye.ai/searchResult?q=YXBwPSJBcGFjaGVEUyI%3D #Infosec #CyberSecurity #ZoomEye

    0000034
    25 followersView on X

Explore more