CVE-2026-92609

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Session fixation in HTTP management authentication allows remote attackers to gain unauthorized access to an authenticated management session via reuse of a session identifier retained across successful authentication. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to version 10.1.1, which fixes the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-384

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-09-25: 209-25
Referenced assets2 URLs
Full discourse2 posts
  • SecAlerts@SecAlertsCo

    🔓 Apache Qpid Broker-J: session fixation in HTTP management auth lets attackers hijack sessions with no creds. CVSS 9.8 critical. CVE-2026-92609 #cybersecurity #ciso #cto #vulnerabilities #mssp https://secalerts.co/vulnerability/CVE-2026-92609?utm_campaign=x https://t.co/iNDvePgBqA

    00000128
    889 followersView on X
  • Daily CyberSecurity@Daily_CyberSec

    New Apache Qpid Broker-J vulnerabilities, including CVE-2026-92609, CVE-2026-92573, and CVE-2026-92564, expose brokers to DoS. Patch immediately. #ApacheQpid #CVE202692609 #CVE202692573 #AMQP #Cybersecurity #Infosec https://securityonline.info/apache-qpid-broker-j-vulnerabilities/

    00000375
    13.0K followersView on X

Explore more