CYBERSECURITYTRACKER
TRACKING6,877 stories in this site build1,441 vulnerability news stories in this site build
Permanent story citation

CVE-2026-68536: Apache MyFaces: Server-Side Request Forgery / Local File Inclusion Vulnerability

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7536

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-68536: Apache MyFaces: Server-Side Request Forgery / Local File Inclusion Vulnerability

Apache MyFaces contains a server-side request forgery and local file inclusion vulnerability affecting versions 2.2 through 4.1. The vulnerability was disclosed on September 16, 2026, with moderate severity.

Why it matters: Organizations running Apache MyFaces must identify affected versions and apply patches to prevent attackers from forging requests or accessing local files on vulnerable systems.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary