Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2614+ Articles
162+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
All tags
17 articles

#Java

All CosmicBytez Labs articles tagged #Java, across news, security advisories, how-to guides, and projects.

  • SecurityAug 28, 2026

    CVE-2026-59354: Spring Security OAuth2 Authorization Server Dynamic Client Registration Flaw

    Critical flaw (CVSS 9.6) in Spring Security Authorization Server 7.0.0-7.0.4 lets a registered client trigger stored XSS, SSRF, or privilege escalation.

  • SecurityAug 12, 2026

    PicketLink SAML Authentication Bypass — Forged Assertions Accepted Without Validation

    CVE-2026-10579 (CVSS 9.8): PicketLink Federation's SAML handler accepts forged assertions, allowing unauthenticated remote attackers to authenticate as any user.

  • NewsJul 27, 2026

    Hackers Target US Firms in FastJson RCE Zero-Day Attacks

    Threat actors are actively exploiting an unpatched remote code execution vulnerability in Alibaba's FastJson Java library, targeting US enterprises with no authentication or user interaction required.

  • NewsJul 26, 2026

    Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patch Available

    A critical unpatched remote code execution flaw in Alibaba's Fastjson 1.x library is being actively exploited in the wild. Tracked as CVE-2026-16723, the...

  • NewsJul 25, 2026

    Fastjson 1.x RCE Actively Exploited With No Patch Available

    Attackers are actively exploiting CVE-2026-16723, a critical remote code execution flaw in Alibaba's Fastjson 1.x library affecting Spring Boot...

  • SecurityJul 24, 2026

    fastjson RCE Without Gadget or AutoType — CVE-2026-16723

    A critical remote code execution flaw in fastjson 1.2.68–1.2.83 requires no AutoType enablement and no classpath gadget, making it exploitable on...

  • SecurityJul 22, 2026

    CVE-2026-64606: Apache Fury Critical Deserialization Flaw (CVSS 9.8)

    A critical deserialization vulnerability in Apache Fury allows attackers to bypass class-registration checks during Java lambda deserialization, enabling...

  • SecurityJul 15, 2026

    CVE-2026-59084: Apache Tomcat EncryptInterceptor Misconfiguration Risk (CVSS 9.1)

    Apache Tomcat's EncryptInterceptor cluster encryption feature has been insufficiently documented since version 9.0.13, leaving deployments vulnerable to...

  • SecurityJun 3, 2026

    CVE-2026-47065: Java Deserialization Filter Bypass via resolveProxyClass (CVSS 9.8)

    A CVSS 9.8 critical Java deserialization vulnerability allows attackers to bypass ObjectInputFilter via TC_PROXYCLASSDESC, circumventing acceptMatchers…

  • SecurityMay 20, 2026

    GlassFish Administration Console Authenticated RCE

    An authenticated Remote Code Execution vulnerability in GlassFish's Administration Console (CVSS 9.1) allows users with panel access to execute arbitrary...

  • SecurityMay 20, 2026

    GlassFish Gadget Handler Expression Language RCE

    A critical CVSS 9.6 Remote Code Execution vulnerability in GlassFish's server-side gadget handler allows attackers to inject Expression Language...

  • SecurityMay 2, 2026

    CVE-2026-42779: Critical Apache MINA Deserialization Class

    An incomplete fix for CVE-2026-41635 leaves Apache MINA 2.1.x and 2.2.x branches exposed to a critical deserialization bypass via...

  • SecurityMay 1, 2026

    Apache MINA Incomplete Deserialization Patch Leaves 2.1.X

    Apache MINA versions 2.1.X and 2.2.X remain vulnerable to unauthenticated remote code execution because the fix for CVE-2026-41409 was never backported,...

  • SecurityApr 28, 2026

    CVE-2026-40860: Apache Camel JMS Unsafe ObjectMessage

    Apache Camel's JmsBinding class in camel-jms and camel-sjms deserializes incoming JMS ObjectMessage payloads via javax.jms.ObjectMessage.getObject()...

  • SecurityApr 28, 2026

    CVE-2026-41635: Apache MINA Class Allowlist Bypass Enables

    Apache MINA's AbstractIoBuffer.resolveClass() contains a branch for static classes and primitive types that skips allowlist validation entirely, letting...

  • SecurityApr 22, 2026

    CVE-2026-22753: Spring Security Filter Chain Bypass via PathPattern Matcher

    A high-severity flaw in Spring Security allows security filter chains to silently fail to match requests when PathPatternRequestMatcher.Builder is used to...

  • SecurityFeb 6, 2026

    Apache Struts Critical RCE via OGNL Injection Returns

    A new critical OGNL injection vulnerability in Apache Struts allows unauthenticated remote code execution, reminiscent of the 2017 Equifax breach vector....