500+ Apache Tika Toolkit Instances Vulnerable to Critical XXE Attack Exposed Online

Over 565 internet-exposed Apache Tika Server instances are vulnerable to a critical XML External Entity (XXE) injection flaw. That could enable attackers to steal sensitive data, launch denial-of-service attacks, or conduct server-side request forgery operations. The vulnerability, tracked as CVE-2025-66516, affects tika-core versions 1.13.0 through 3.2.1 and carries a maximum CVSS severity score of 10.0. […]

The post 500+ Apache Tika Toolkit Instances Vulnerable to Critical XXE Attack Exposed Online appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: