Apache disclosed CVE-2026-64608, a critical vulnerability in the Apache Fory C++ implementation that can cause heap type confusion and out-of-bounds read/write during deserialization. The flaw occurs in compatible mode when field-skip paths do not properly validate declared field types against the actual data being processed, creating a memory-corruption condition that could have severe impact on affected deployments.
The issue affects Apache Fory C++ versions 0.14.0 through before 1.4.0 and does not affect other Apache Fory language implementations. Apache has advised users to upgrade to 1.4.0 to remediate the bug. The vulnerability was reported by Nguyen Van Hiep (@hypnguyen1209) of MBBank, and CISA SSVC metadata indicates no known exploitation so far, while noting the issue may be automatable and carries total technical impact.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
The CVE-2026-64608 record was updated on 2026-07-21 with a CVSS v3.1 vector indicating critical impact and CISA SSVC metadata. The metadata noted no known exploitation, automatable exploitation potential, and total technical impact.
Apache recommended upgrading affected Apache Fory C++ deployments to version 1.4.0 to remediate CVE-2026-64608. The fix guidance accompanied the public disclosure of the vulnerability.
A security advisory disclosed CVE-2026-64608, a heap type confusion flaw that can lead to out-of-bounds read and write during deserialization in Apache Fory C++ compatible mode. The advisory states that versions 0.14.0 before 1.4.0 are affected and that other language implementations are not impacted.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourceseclists.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.