chiprook
← Security
SecurityOctober 6, 2026, 23:20

CVE-2026-103877: Apache Directory LDAP API deserialization flaw risks RCE

A CWE-502 deserialization flaw, CVE-2026-103877, was disclosed on October 2, 2026 in the Apache Directory LDAP API alongside five sibling issues. Apache fixed it in versions 2.1.9 and 1.2.9; there is no reported exploitation in the wild or public proof-of-concept.

CVE-2026-103877: Apache Directory LDAP API deserialization flaw risks RCE
#Apache
Read next
Security

vCenter Syslog directory traversal CVE-2026-59310 exploited for RCE

Security

Satori and Next.js SVG escaping flaw led to RCE risk

Security

N-able N-central Pre-Auth RCE Highlights RMM Concentration Risk

Security

CVE-2026-81657 in IBM Guardium: deserialization flaw rated 9.8