
Apache CXF CVE-2026-44417: Incomplete fix for CVE-2025-48913 Untrusted JMS configuration can lead to RCE https://www.openwall.com/lists/oss-security/2026/05/22/7 CVE-2026-44618: XXE in WS-Transfer functionality https://www.openwall.com/lists/oss-security/2026/05/22/8 CVE-2026-44930: LDAP Injection in XKMS LDAP Repository https://www.openwall.com/lists/oss-security/2026/05/22/9
Post summary
The post announces three new Apache CXF CVEs, briefly describes each vulnerability type, and links to discussion threads, without providing PoC, exploit, or patch details.


