TL;DR
The Apache Software Foundation released patches to address high-severity Apache NiFi vulnerabilities alongside a critical flaw in Apache MyFaces. These software defects expose enterprise data pipelines and web applications to file system manipulation and Denial of Service attacks. Administrators must apply the latest Apache security updates immediately.
- Total: 3 CVEs
- Severity: 1 High · 2 Unrated
- Actively exploited: None confirmed
- Highest severity: 7.2 (High · CVSSv4) — CVE-2026-87976
- Action: Apply the latest security updates now
Track every Apache CVE the moment it's exploited.
Get free email alertsNotable CVEs
| CVE | CVSS (CVSSv4) | Type | Status |
|---|---|---|---|
| CVE-2026-87976 | 7.2 | Improper Limitation of Pathname in Persisted Extension Bundles | Not exploited |
| CVE-2026-70469 | Awaiting analysis | Improper Handling of Case Sensitivity for Content-Encoding in HTTP Requests | Not exploited |
| CVE-2026-76646 | Awaiting analysis | Denial of Service via Unbounded Request Parsing | Not exploited |
Why It Matters
Apache NiFi automates cybersecurity, observability, event streams, and generative AI data pipelines for thousands of companies worldwide across every industry. Therefore, successful exploitation of these platforms can disrupt critical data flows and compromise sensitive enterprise information.
How the Attacks Work
The first of the Apache NiFi vulnerabilities, CVE-2026-87976 (High severity), involves improper limitation of pathnames in persisted extension bundles. Authenticated users authorized to write and delete bundles can upload a NAR with a crafted manifest. Because the default file persistence provider used coordinates as filesystem path components without rejecting parent-directory names, this results in file operations outside of the designated directory.
The second issue, CVE-2026-70469 (High severity), affects HTTP request handling. The framework failed to properly validate multiple instances of the Content-Encoding header or reject non-standard gzip identifiers. A malicious client can send crafted requests to consume excessive memory, leading to a crash.
Additionally, a critical flaw (CVE-2026-76646) affects Apache MyFaces. A remote attacker could cause excessive resource consumption by supplying specially crafted request parameters, potentially resulting in a denial of service condition.
Affected Versions and Mitigation
The path manipulation defect impacts NiFi Registry 0.4.0 through 2.11.0, while the HTTP memory exhaustion bug affects NiFi 2.11.0. To mitigate these risks, users must upgrade to version 2.12.0 via the official Apache NiFi downloads page.
The MyFaces flaw impacts branches 2.2.0 through 4.1.3. Maintainers advise upgrading to patched versions such as 2.3.12, 3.0.4, 4.0.4, or 4.1.4, accessible through the MyFaces download portal. Currently, no active in-the-wild exploitation of these flaws has been confirmed.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!