Apache disclosed CVE-2026-66713, a deserialization-of-untrusted-data flaw in the Tribes-based clustering component of Apache Axis2/Java that can lead to remote code execution. The issue affects Axis2/Java through version 2.0.0 and is reachable when deployed with Apache Tomcat Tribes clustering enabled; an unauthenticated attacker with network access to the clustering port can send a crafted serialized Java object that is deserialized in org.apache.axis2.clustering.tribes.Axis2ChannelListener#messageReceived. Apache and CVE records describe the attack as requiring no privileges or user interaction, with a CVSS:3.1 vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
Apache recommends upgrading to Axis2/Java 2.0.1, which fixes the issue by removing the clustering feature entirely. A related repository commit deletes the modules/clustering component along with associated classes, tests, configuration references, and dependencies, reflecting the project's decision to eliminate the vulnerable functionality rather than patch it in place. The vulnerability was credited to liuhuajin of Huawei, and available advisories indicate no known exploitation at the time of publication; the feature is noted as off by default, limiting exposure to deployments that explicitly enabled Tribes clustering.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
The CVE-2026-66713 record was updated with a CVSS v3.1 vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H and a CISA SSVC entry. The update stated there was no known exploitation, the attack was automatable, and the total technical impact was high.
Apache disclosed CVE-2026-66713, a deserialization of untrusted data vulnerability affecting Axis2/Java through version 2.0.0 in its Tribes-based clustering component. The advisory said unauthenticated remote code execution is possible when Tomcat Tribes clustering is enabled and recommended upgrading to version 2.0.1, which removes the clustering feature; the issue was credited to liuhuajin of Huawei.
A GitHub commit labeled "AXIS2-6097 Remove Clustering feature" removed the clustering component from Apache Axis2/Java, including related classes, tests, configuration references, and dependencies. The change is associated with version 2.0.1 and eliminates the vulnerable feature later cited in CVE-2026-66713.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
6 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecve.org
Open sourceseclists.org
Open sourcelists.apache.org
Open sourceopenwall.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.