Apache ZooKeeper security materials list two newly assigned vulnerability identifiers, CVE-2026-24281 and CVE-2026-24308. The supplied CVE records do not provide vulnerability descriptions, affected versions, severity ratings, exploit conditions, or remediation guidance.
A related Apache ZooKeeper issue, ZOOKEEPER-4986, calls for disabling reverse-DNS lookups in TLS clients and servers. Organizations running ZooKeeper should review the project’s security advisories and release notes, identify deployed versions, and assess TLS/DNS configuration changes before applying relevant updates or mitigations.

See affected versions and whether adversaries are exploiting it.
4 references tracked. Mallory keeps watching after this page renders.
cve.org
Open sourcecve.org
Open sourcezookeeper.apache.org
Open sourceissues.apache.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.