
🚨 Two new CVEs in Apache Solr — and they’re hitting where teams least expect it. CVE-2026-22022 and CVE-2026-22444 expose gaps in authorization and file access controls — putting sensitive configuration data, file systems, and even credentials at risk. Why this matters: ✔️ No authentication required for certain exploit paths ✔️ Sensitive data exposure through misconfigured APIs ✔️ Widely used versions affected across enterprise environments Moving from Solr 8 to 9+ can mean Java upgrades, API changes, and months of migration work... HeroDevs Never-Ending Support (NES) for Apache Solr & Lucene delivers patched, drop-in replacements for EOL versions — so you can remediate now and migrate on your timeline. Because security issues don’t wait for your roadmap. #ApacheSolr #Java #CVE #AppSec #OpenSourceSecurity #EOL #DevSecOps #HeroDevs
Post summary
Two new CVEs in Apache Solr expose authorization and file‑access control gaps, risking sensitive configuration data and credentials. HeroDevs NES offers patched replacements for affected EOL versions.
