https://cxf.apache.org/security-advisories.html
https://lists.apache.org/thread/c7vb015f8ljmjl44030mn0yfq71f7sd7
https://lists.apache.org/thread/c1zqxppo1m5z3kbdhjn5p991zk09ynkh
https://lists.apache.org/thread/nr1l8k9kgq4rx61ytfkq0bt8w549o1rv
Severity: Critical
ID: 317386
File Name: apache_cxf_4_2_1.nasl
Version: 1.2
Type: Local
Agent: windows, macosx, unix
Family: Misc.
Published: 5/28/2026
Updated: 5/29/2026
Configuration: Enable thorough checks (optional)
Supported Sensors: Nessus Agent, Nessus
Risk Factor: High
Score: 8.4
Risk Factor: Critical
Base Score: 10
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
CVSS Score Source: CVE-2026-44930
Risk Factor: Critical
Base Score: 9.8
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:/a:apache:cxf
Required KB Items: installed_sw/Apache CXF
Patch Publication Date: 5/22/2026
Vulnerability Publication Date: 5/22/2026
CVE: CVE-2026-44417, CVE-2026-44618, CVE-2026-44930
IAVB: 2026-B-0135