Apache disclosed CVE-2026-64609, an out-of-bounds read vulnerability in Apache Fory (formerly Apache Fury) caused by use of sun.misc.Unsafe during out-of-band zero-copy Java deserialization. The flaw occurs in readAlignedVarUint(), which can read beyond the underlying buffer bounds, and is tracked as CWE-125. The issue carries a CVSS v3.1 score reflecting network-exploitable impact with no privileges or user interaction required: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H.
The vulnerability affects Apache Fory versions 0.5.0 through before 1.4.0, including releases published before 0.11.0 under the Maven coordinates org.apache.fury:fury-core. Apache said the bug only affects applications that explicitly enable the opt-in out-of-band zero-copy deserialization feature, and recommended upgrading to version 1.4.0 to remediate the issue. Available disclosure data indicates no known exploitation so far, though the flaw is considered automatable and can cause partial technical impact.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Apache recommended upgrading to version 1.4.0 to remediate CVE-2026-64609. The fixed release addresses the out-of-bounds read vulnerability in the zero-copy deserialization feature.
A vulnerability identified as CVE-2026-64609 was disclosed in Apache Fory (formerly Apache Fury) as an out-of-bounds read caused by use of sun.misc.Unsafe during opt-in out-of-band zero-copy Java deserialization. The issue affects versions 0.5.0 before 1.4.0, including older releases published as org.apache.fury:fury-core.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourceseclists.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.