PatchSiren cyber security CVE debrief
CVE-2026-64606 Apache CVE debrief
A deserialization of untrusted data vulnerability exists in Apache Fory, potentially allowing class-registration checks to be bypassed during Java lambda deserialization. The issue affects Apache Fory versions before 1.4.0. Users are advised to upgrade to version 1.4.0, which fixes the issue. This vulnerability has a CVSS score of 9.8 and is considered CRITICAL. The vulnerability is related to the lambda capture class and can be exploited through deserialization of untrusted data. The affected product or component is Apache Fory, and the likely operational impact is security breaches and exploitation of the affected systems.
- Vendor
- Apache
- Product
- Fory
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-27
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-27
Who should care
Users of Apache Fory versions before 1.4.0 should be concerned about this vulnerability as it could allow for class-registration checks to be bypassed during Java lambda deserialization. This could potentially lead to security breaches and exploitation of the affected systems. Affected operators, platforms, vulnerability-management, and security teams should review and address this vulnerability.
Technical summary
The vulnerability is caused by deserialization of untrusted data in Apache Fory, specifically affecting the lambda capture class. This issue allows for class-registration checks to be bypassed during Java lambda deserialization. The affected versions are Apache Fory before 1.4.0. The CVSS vector for this vulnerability is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. This vulnerability has a CVSS score of 9.8 and is considered CRITICAL.
Defensive priority
High
Recommended defensive actions
- Upgrade Apache Fory to version 1.4.0 or later
- Review and monitor Apache Fory usage for potential exploitation attempts
- Implement compensating controls to mitigate potential impacts
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The CVE record was published on 2026-07-21T11:16:27.973Z and was last modified on 2026-07-27T13:47:41.580Z. The NVD entry is currently Analyzed. This information is based on the provided source corpus and may not reflect the full scope of the vulnerability. Further verification is recommended to ensure accurate understanding of the issue. The source detail is limited, and evidence limits should be considered during verification.
Official resources
-
CVE-2026-64606 CVE record
CVE.org
-
CVE-2026-64606 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory, Issue Tracking
-
Mitigation or vendor reference
af854a3a-2127-422b-91ae-364da2661108 - Third Party Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T11:16:27.973Z and has not been modified since then. The NVD entry is currently Analyzed.