CVE-2026-64606
Apache Fory versions before 1.4.0 are vulnerable to a deserialization flaw that can be triggered by untrusted data. The flaw allows attackers to bypass class‑registration checks during Java lambda deserialization, potentially leading to arbitrary code execution. The issue is critical and requires immediate attention.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Apache Fory installations older than version 1.4.0.
Real-world impact
An attacker who can supply crafted data to the application can execute arbitrary code on the affected system, compromising confidentiality, integrity, and availability.
Why this severity
The CVSS score of 9.8 reflects that the vulnerability is network‑exposed, has low attack complexity, requires no privileges or user interaction, and can fully compromise confidentiality, integrity, and availability.
What to do about it
- 01Upgrade Apache Fory to version 1.4.0 or later.
- 02Restart the application or service to apply the update.
NVD-referenced vendor advisory
Timeline
- Jul 21, 2026 · 12d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 21, 2026 · 12d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
- Jul 27, 2026 · 6d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- lists.apache.org/thread/py6fbvm9nk1gxdd85rbz…vendor advisoryissue tracking
- openwall.com/lists/oss-security/2026/07/…third party advisory