Red Hat released security updates for its Apache Camel distributions for Spring Boot and Quarkus to fix multiple vulnerabilities, including remote code execution and arbitrary code execution flaws tied to unsafe deserialization. Advisory RHSA-2026:17668 updates Red Hat Build of Apache Camel 4.18.1 for Spring Boot, while RHSA-2026:22453 updates Red Hat Build of Apache Camel 4.18 for Quarkus 3.33 to 3.33.1.GA. The advisories also address additional high-impact issues across bundled components such as Jetty, Netty, Apache Artemis, Kafka Clients, Bouncy Castle, Plexus Utils, and Apache MINA, covering risks including authentication bypass, request smuggling, denial of service, directory traversal, arbitrary file write, and information disclosure.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
Red Hat published security advisory RHSA-2026:22453 for Red Hat Build of Apache Camel 4.18 for Quarkus 3.33 and released update RHBQ 3.33.1.GA. The Important-rated update fixes CVE-2026-40858, CVE-2026-40860, CVE-2026-6857, and CVE-2026-2332 in bundled Apache Camel and Jetty components.
A Red Hat Bugzilla entry described CVE-2026-6857 as an unsafe deserialization flaw in camel-infinispan's ProtoStream remote aggregation repository and said the issue had been reported to the security team and to MITRE under CVE Request #2024308. The entry states Red Hat addressed the flaw in Red Hat Build of Apache Camel 4.18.1 for Spring Boot 3.5.14 and Red Hat Build of Apache Camel 4.18 for Quarkus 3.33 via RHSA-2026:17668 and RHSA-2026:22453.
Red Hat published security advisory RHSA-2026:17668 announcing a patch release and security update for Red Hat Build of Apache Camel 4.18.1 for Spring Boot. The update fixes numerous vulnerabilities across Apache Camel, Spring Boot, Netty, Jetty, Apache Artemis, Kafka Clients, Bouncy Castle, Plexus Utils, and Apache MINA.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.