CVE-2026-103877: Apache Directory LDAP API deserialization flaw risks RCE
A CWE-502 deserialization flaw, CVE-2026-103877, was disclosed on October 2, 2026 in the Apache Directory LDAP API alongside five sibling issues. Apache fixed it in versions 2.1.9 and 1.2.9; there is no reported exploitation in the wild or public proof-of-concept.
- Affected ranges: 2.1.0 before 2.1.9 and 1.2.0 before 1.2.9
- A rogue server replies with a serialized Java class instead of schema data
- No credentials needed: the client initiates the exchange
- ZoomEye reports 154 ApacheDS assets; no exploitation reported
Read next
Security