
🔐 Apache WSS4J (CVSS 9.8): unauthenticated attackers can forge authenticated SOAP messages via crafted unsigned SAML sender-vouches assertions. CVE-2026-88920 hits the DOM security processor. Patch now. #cybersecurity #ciso #cto https://secalerts.co/vulnerability/CVE-2026-88920?utm_campaign=x https://t.co/khwjGd3oG7
