Vulnerabilities

Second Apache OFBiz Vulnerability Exploited in Attacks

CISA is warning organizations that a second Apache OFBiz flaw is being exploited in the wild shortly after the release of PoC exploits.

Apache vulnerability

The US cybersecurity agency CISA on Tuesday added a second Apache OFBiz flaw to its Known Exploited Vulnerabilities (KEV) catalog.

The vulnerability, tracked as CVE-2024-38856, has been described as an incorrect authorization issue that can allow unauthenticated endpoints to execute screen rendering code under certain conditions. 

Apache OFBiz versions through 18.12.14 are impacted, and version 18.12.15 includes a fix.  

SonicWall, whose researchers discovered the vulnerability, described it as a critical issue that can allow unauthenticated remote code execution.

Proof-of-concept (PoC) exploits targeting CVE-2024-38856 started emerging after the flaw’s disclosure in early August, and now CISA is warning organizations about attacks exploiting the weakness

No information has been shared about the attacks. 

Advertisement. Scroll to continue reading.

CVE-2024-38856 is the second Apache OFBiz vulnerability that has been exploited in attacks in recent weeks. 

The other flaw, tracked as CVE-2024-32113, was discovered in May and exploitation attempts were first spotted in late July. This is a path traversal bug that could lead to remote command execution.

The SANS Technology Institute’s Internet Storm Center reported seeing evidence that threat actors may have tried to add an exploit for CVE-2024-32113 to variants of the Mirai botnet. 

Apache OFBiz, a free framework for creating ERP applications, is used by many companies, mainly in the United States, but also in India and Europe. 

Related: Critical Apache OFBiz Vulnerability in Attacker Crosshairs

Related: CISA Warns of Exploited Vulnerabilities Impacting Dahua Products

Related: CISA Warns of Avtech Camera Vulnerability Exploited in Wild

Related Content

Vulnerabilities

Multiple espionage-motivated threat actors have adopted BlueMoon in opportunistic, rushed deployments.

Vulnerabilities

The critical-severity path traversal flaw allows unauthenticated attackers to read arbitrary files from the GitLab server.

Vulnerabilities

Tracked as CVE-2026-85102 and CVE-2026-85103, the flaws could be exploited for remote code execution.

Vulnerabilities

A Russian threat actor used AI to build, test, and deploy exploits against hundreds of organizations worldwide.

Vulnerabilities

Tracked as CVE-2026-19490, the authentication bypass flaw has been exploited in the wild since at least September 3.

Vulnerabilities

Cisco and CISA have flagged exploitation of CVE-2026-20079, a vulnerability disclosed in March 2026.

Malware & Threats

The high-severity, unauthenticated vulnerability tracked as CVE-2025-25249 was patched in January 2026.

Mobile & Wireless

The security updates resolve critical flaws across Android’s Framework, System, and Kernel components.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version