Multiple vulnerabilities in Sonatype Nexus Repository Manager (CVSS Base Score 7.5) allow a remote, anonymous attacker to bypass security measures, disclose information, and potentially manipulate data. The affected versions are all releases prior to version 3.94.0, and users must upgrade to Nexus Repository Manager 3.94.0 to mitigate the threat.
[WID-SEC-2026-2360] Sonatype Nexus Repository Manager: Mehrere Schwachstellen CVSS Base Score 7.5 (hoch) CVSS Temporal Score 6.5 (mittel) Remoteangriff ja Datum 14.07.2026 Stand 15.07.2026 Mitigation ja Betroffene Systeme Betriebssystem Linux Sonstiges UNIX Windows Produktbeschreibung Sonatype Nexus Repository Manager ist ein Verwaltungstool für Software-Bestandteile. Produkte 14.07.2026 Sonatype Nexus Repository Manager <3.94.0 Angriff Angriff Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Sonatype Nexus Repository Manager ausnutzen, um Sicherheitsmaßnahmen zu umgehen, um Informationen offenzulegen und ggf. Daten zu manipulieren. CVE Informationen Versionshistorie Feedback zum Advisory geben