A critical vulnerability (CVSS 9.8) in Apache Axis2 allows an unauthenticated remote attacker to execute arbitrary code. The flaw affects Apache Axis2 versions prior to 2.0.1. A mitigation is available, but the article does not specify a patched version or provide the CVE identifier.
[WID-SEC-2026-2540] Apache Axis2: Schwachstelle ermöglicht Codeausführung CVSS Base Score 9.8 (kritisch) CVSS Temporal Score 8.5 (hoch) Remoteangriff ja Datum 27.07.2026 Stand 28.07.2026 Mitigation ja Betroffene Systeme Betriebssystem Linux Sonstiges UNIX Windows Produktbeschreibung Axis2 ist eine Web-Service / SOAP / WSDL Engine. Produkte 27.07.2026 Apache Axis2 <2.0.1 Angriff Angriff Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Apache Axis2 ausnutzen, um beliebigen Programmcode auszuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben