A critical flaw tracked as CVE-2026-59099 was disclosed in Apereo CAS, the open-source single sign-on platform, affecting versions 7.3.0 through 8.0.0-RC5. The bug stems from AES-GCM nonce reuse caused by a fixed all-zero IV being used with the same encryption key for the life of the server, allowing an unauthenticated remote attacker to collect client-side webflow execution tokens from the login page and use known-plaintext techniques to decrypt webflow conversation state. The issue can expose sensitive session, identity, and application data, and was rated critical with CVSS 4.0 9.3 and CVSS 3.1 9.1.
The disclosure highlights how cryptographic implementation mistakes can turn protected traffic or tokens into recoverable plaintext, echoing earlier SSL/TLS weaknesses such as attacks against RC4 that similarly enabled partial plaintext recovery from encrypted sessions. Apereo was notified on June 16, fixed the issue on June 17, and released patched versions on June 18; affected organizations were urged to upgrade to 8.0.0-RC6 or the relevant patch release and to rotate signing and encryption keys if they had operated vulnerable deployments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
On June 18, 2026, Apereo published patch releases for the critical CAS cryptographic flaw CVE-2026-59099. Organizations were advised to upgrade to 8.0.0-RC6 or apply the relevant patch release and rotate signing and encryption keys if they had run a vulnerable version.
Apereo fixed CVE-2026-59099 on June 17, 2026 after being notified the previous day. The issue stemmed from reuse of a fixed all-zero IV with AES-GCM across the server lifetime.
Apereo was notified on June 16, 2026 of a critical AES-GCM nonce reuse vulnerability in Apereo CAS affecting versions 7.3.0 through 8.0.0-RC5. The flaw allowed unauthenticated remote attackers to decrypt webflow conversation state from collected login-page tokens.
Imperva’s Application Defense Center disclosed the “Bar Mitzvah” attack, which exploits the long-known RC4 Invariance Weakness to recover partial plaintext from SSL/TLS traffic using RC4. The company said the attack could expose sensitive data from the first 100 bytes of traffic and urged administrators, users, and browser vendors to disable or remove RC4 support.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
threataft.com
Open sourceblogs.technet.com
Open sourcesecurityweek.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.