
CVE-2026-38165 - SSTI to RCE in XDocReport's Velocity integration. If an application processes untrusted docx templates with XDocReport + Apache Velocity, attacker-controlled VTL can reach Java classes and execute commands in the context of the application https://gist.github.com/win3zz/34374c553effdd8fa559390883da7b86 https://t.co/Fd11nmUSMP
Post summary
The post announces CVE-2026-38165 as a server‑side template injection leading to remote code execution, linking to a Gist PoC that likely contains exploit code, but makes no claims of active exploitation or patches.

