Critical Alert 4 Active Exploits Detected Today

CVE-2026-93952 Arista VeloCloud Orchestrator Improper Input Validation Vulnerability →
CVE-2026-94127 F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability →
CVE-2026-93616 Check Point Multiple Products Path Traversal Vulnerability →
CVE-2026-85102 Check Point Multiple Products Improper Certificate Validation Vulnerability →
Powered by CVE Watchtower
×

CVE Watchtower

← Back to CVE List

CVE-2026-68536NVD

Vulnerability Summary

Server-Side Request Forgery / Local File Inclusion in Apache MyFace Core.

Older unsupported versions may also be affected. 

Users are recommended to upgrade to versions 2.3.12, 2.3-next-M9, 3.0.4, 4.0.4, or 4.1.4, which fix this issue.
Severity Level
UNKNOWN
Published Date
Sep 16, 2026
Last Modified
Sep 17, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
0.47%Probability
Root Weakness (CWE)
Refer to the official MITRE database for detailed architectural specifications regarding this weakness.

Affected & Patched Versions

Affected Versions
  • Apache Software Foundation Apache MyFaces >= 2.2.0-beta and <= 2.2.15
  • Apache Software Foundation Apache MyFaces >= 2.3.0
  • Apache Software Foundation Apache MyFaces >= 2.3-next-M1 and < 2.3-next-M9
  • Apache Software Foundation Apache MyFaces >= 2.3.1 and < 2.3.12
  • Apache Software Foundation Apache MyFaces >= 3.0.0 and < 3.0.4
  • Apache Software Foundation Apache MyFaces >= 4.0.0 and < 4.0.4
  • Apache Software Foundation Apache MyFaces >= 4.1.0 and < 4.1.4
Patched Versions
  • Apache Software Foundation Apache MyFaces 2.2.15
  • Apache Software Foundation Apache MyFaces 2.3-next-M9
  • Apache Software Foundation Apache MyFaces 2.3.12
  • Apache Software Foundation Apache MyFaces 3.0.4
  • Apache Software Foundation Apache MyFaces 4.0.4
  • Apache Software Foundation Apache MyFaces 4.1.4
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.