
CVE-2026-23794: Apache Syncope: Reflected XSS on Enduser Login https://www.openwall.com/lists/oss-security/2026/02/02/1 CVE-2026-23795: Apache Syncope: Console XXE on Keymaster parameters https://www.openwall.com/lists/oss-security/2026/02/02/2
Post summary
The post lists two new Apache Syncope CVEs with brief vulnerability types—Reflected XSS and XXE—but offers no PoC, exploit, patch, or evidence of active exploitation.


