Apache disclosed CVE-2026-64606, a critical deserialization vulnerability in Apache Fory that lets attackers bypass class-registration checks during Java lambda deserialization through an auto-admitted SerializedLambda capturing interface. The flaw is tracked as CWE-502 and carries a CVSS 3.1 score reflecting network-exploitable, no-authentication impact with potential compromise of confidentiality, integrity, and availability.
The issue affects org.apache.fory:fory-core versions from 0.11.0 before 1.4.0 and the earlier package line org.apache.fury:fury-core from 0.5.0 before 0.11.0. Apache said the vulnerability was reported by Charles Vosburgh and fixed in Apache Fory 1.4.0; users are advised to upgrade immediately. A CISA SSVC entry listed exploitation as none observed, automatable: yes, and technical impact: total.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
On the oss-sec mailing list, Apache Fory disclosed CVE-2026-64606 as a deserialization of untrusted data vulnerability that can bypass class-registration checks via a SerializedLambda capturing interface. The notice credited Charles Vosburgh as the reporter and advised users to upgrade to version 1.4.0.
Apache Fory addressed CVE-2026-64606, a deserialization flaw that could bypass class-registration checks during Java lambda deserialization, by releasing version 1.4.0. The issue affects earlier Apache Fory and Apache Fury package lines identified in the advisories.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourceseclists.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.