a
apache software foundation
Security Risk Profile
72
/100
highSecurity Risk Score
Comprehensive risk assessment based on 395 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from June 1, 1998 to present
395
Total CVEs
2
Critical+High
0
Exploited
2
Unpatched
Threat Assessment
Avg CVSS
8.5
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
2
Critical/High
Risk Level
72/100
high
📈 3 in Last 30 Days
Severity Distribution
Critical
2High
0Medium
1Low
0Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
0Age Distribution
Common Weaknesses (CWE)
1
Path Traversal
1
2
Input Validation
1
Most Affected Products
1. Apache Software Foundation Camel81
2. Apache Software Foundation ActiveMQ45
3. Apache Software Foundation Spark39
4. Apache Software Foundation Hadoop35
5. Apache Software Foundation Kafka30
Recent Vulnerabilities
See more →EOL-apache-hop-2.19
unknown
Aug 17, 2026
EOL-apache-groovy-5.1
unknown
Aug 15, 2026
EOL-apache-camel-4.22
unknown
Aug 11, 2026
EOL-hbase-3.0
unknown
Aug 5, 2026
CVE-2026-66755
CVSS 5.9medium
Apache Tika: Arbitrary Local File Read in ISArchiveParser
Jul 30, 2026
CVE-2026-66713
CVSS 9.8critical
Apache Axis2/Java: deserialization of untrusted Data
Jul 28, 2026🔧 No Patch
https://seclists.org/oss-sec/2026/q3/290
unknown
CVE-2026-66713: Apache Axis2/Java: deserialization of untrusted Data
Jul 27, 2026🔧 No Patch
EOL-apache-activemq-6.3
unknown
Jul 24, 2026
https://seclists.org/oss-sec/2026/q3/162
unknown
CVE-2026-59173: Apache Traffic Server is vulnerable to stalled HTTP/2 flow-control
Jul 17, 2026🔧 No Patch
EOL-apache-spark-4.2
unknown
Jul 14, 2026
Monitor apache software foundation in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.