CVE-2026-50076
Apache Fory’s Java SDK before version 1.1.0 has a critical flaw that lets attackers deserialize crafted data without proper checks. This can allow remote code execution on any system running the vulnerable SDK. The issue is fixed in newer releases.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Apache Fory SDK versions earlier than 1.1.0 running on Java/JVM platforms.
Real-world impact
An attacker who can send malicious serialized data to an application using the vulnerable SDK can run arbitrary code, potentially taking full control of the affected system.
Why this severity
The CVSS score of 9.1 reflects a network‑accessible vulnerability that requires no user interaction, has low complexity, and grants attackers full confidentiality and integrity compromise. The lack of authentication or privilege escalation steps makes it highly dangerous.
What to do about it
- 01Upgrade Apache Fory to version 1.1.0 or later.
- 02Restart any services or applications that use the SDK to ensure the new version is loaded.
NVD-referenced vendor advisory
Timeline
- Jun 4, 2026 · Jun 4, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 22, 2026 · 13d agoAdvisory updatedThe NVD record was last revised.
- Jul 24, 2026 · 11d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- fory.apache.org/securityvendor advisory
- openwall.com/lists/oss-security/2026/06/…mailing listthird party advisory