SecAlerts
a

apache

Security Risk Profile

55
/100
medium

Security Risk Score

Comprehensive risk assessment based on 1000 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from June 11, 2026 to present

1000
Total CVEs
388
Critical+High
1
Exploited
351
Unpatched

Threat Assessment

Avg CVSS
7.4
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
351
Critical/High
Risk Level
55/100
medium
⚠️ 1 Active Exploits🆕 127Fresh (<7d)📈 341 in Last 30 Days

Severity Distribution

Critical
131
High
257
Medium
183
Low
16

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
3

Age Distribution

Common Weaknesses (CWE)

1
Input Validation
50
2
XSS
32
3
Path Traversal
29
4
Infoleak
25
5
SSRF
24

Most Affected Products

1. Apache Tomcat206
2. Apache Traffic Server159
3. Apache Syncope145
4. Apache Camel145
5. Apache CXF77

Recent Vulnerabilities

See more →
CVE-2026-97395
unknown

Apache Polaris: Allows authorized table writers to redirect server-side Iceberg FileIO requests to attacker-controlled endpoints using operation-scoped storage credentials

Sep 29, 2026🔧 No Patch
https://seclists.org/oss-sec/2026/q3/999
unknown

CVE-2026-97395: Apache Polaris: Allows authorized table writers to dict server-side Iceberg FileIO quests to attacker-controlled endpoints using operation-scoped storage cdentials

Sep 29, 2026🔧 No Patch
CVE-2026-71897
CVSS 4.3medium

Apache DolphinScheduler: Allows unauthorized workflow operations through batch-copy and batch-move endpoints

Sep 29, 2026🔧 No Patch
CVE-2026-71898
CVSS 4.3medium

Apache DolphinScheduler: Improper Authorization Allows Project Read-Only Users to Execute Workflows and Tamper with Workflow Definitions

Sep 29, 2026🔧 No Patch
CVE-2026-71899
unknown

Apache DolphinScheduler: Missing Authorization in query-dynamic-sub-workflows API Leads to Information Disclosure

Sep 29, 2026🔧 No Patch
CVE-2026-78214
CVSS 5.3medium

Apache DolphinScheduler: Actuator Endpoint Authentication Bypass via Percent-Encoded Paths

Sep 29, 2026🔧 No Patch
CVE-2026-81569
CVSS 4.3medium

Apache DolphinScheduler: Improper Authorization in Sub-Workflow Tasks Allows Unauthorized Workflow Execution

Sep 29, 2026🔧 No Patch
CVE-2026-82804
unknown

Apache DolphinScheduler: Command Injection in the Alert Script Plugin

Sep 29, 2026🔧 No Patch
CVE-2026-66083
unknown

Apache DolphinScheduler: Unauthorized Disclosure of Data Source Information via /datasources/unauth-datasource

Sep 29, 2026🔧 No Patch
https://seclists.org/oss-sec/2026/q3/998
unknown

CVE-2026-82804: Apache DolphinScheduler: Command Injection in the Alert Script Plugin

Sep 29, 2026🔧 No Patch

Monitor apache in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.