LIVE · cybersecurity feed
Live wire
vendor

Eclipse

26 CVEs published in the last four months and 2 stories. Exploited flaws first.

Critical7
High19
Medium0
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-91589.8critical4diac forteIn Eclipse 4diac FORTE versions 3.0.0 to 3.1.0, a specially crafted DELETE connection command to the management int79d ago
CVE-2026-164419.6criticalopenj9In Eclipse OpenJ9 versions up to 0.60, when executing class files where a previously concrete superclass method ha46d ago
CVE-2026-25879.6criticalglassfishA critical Remote Code Execution (RCE) vulnerability was identified in the server-side template rendering mechanism109d ago
CVE-2026-126059.6criticalglassfishIn Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `g30d ago
CVE-2026-25869.1criticalglassfishAn authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console.109d ago
CVE-2026-164399.1criticalopenj9In Eclipse OpenJ9 versions up to 0.60, using -Xtrace to trace method arguments can lead to buffer underflow.46d ago
CVE-2026-100509.1criticaljettyIn Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes.32d ago
CVE-2026-446918.8hightheiaIn Eclipse Theia versions prior to 1.69.0, custom task definitions in workspace files (e.g.79d ago
CVE-2026-446888.8hightheiaIn Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory names as part 79d ago
CVE-2026-600098.8hightheiaIn Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /file-upload` in31d ago
CVE-2026-465808.8hightheiaIn Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in a workspace wer79d ago
CVE-2026-95618.2highkuraEclipse Kura versions prior to 5.6.2 trust the client-supplied X-Forwarded-For HTTP header as the authoritative sou53d ago
CVE-2026-580808.2highmiloIn Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy()` fails to preserve a configured `RoleMappe32d ago
CVE-2026-613877.5highmiloIn Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota accounting is not exception-safe: if item creat32d ago
CVE-2026-629277.5highmiloIn Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the original mixed batch to address-spac32d ago
CVE-2026-632527.5highmiloIn Eclipse Milo versions 0.6.0 through 1.1.4, UASC server transport handlers fail to release retained partial mess32d ago
CVE-2026-126097.5hightheiaIn Eclipse Theia versions 1.66.0 and up until including 1.73.1, the `@theia/plugin-ext` backend exposes the `/host31d ago
CVE-2026-465817.5highmojarraIn Eclipse Mojarra versions 2.3 and following, URL handing in `DefaultFaceletFactory` does not properly sanitize a31d ago
CVE-2026-115767.5highthreadx netx duoThe security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors error handling in the HTTP server PUT pro78d ago
CVE-2026-100517.5highjettyIn Eclipse Jetty, a first HTTP/1.1 request with trailers causes the server to retain the trailers in subsequent re53d ago
CVE-2026-150757.5highvert.xIn Eclipse Vert.x versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), DefaultRedirectHandler 53d ago
CVE-2026-150767.5highvert.xIn versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), the WebClientSession component of Ecli53d ago
CVE-2026-618917.5hightheiaIn Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend exposes HTTP file-download e31d ago
CVE-2026-162437.5highomrIn Eclipse OMR versions up to 0.11, the arraycmp SIMD implementation for Z and P does not check if the number of b46d ago
CVE-2024-77087.5highjettyFor requests that have a body, but reading the body may end up in reading 0 bytes, there is a buffer leak.53d ago
CVE-2026-600077.4highmiloIn Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid32d ago

Filter the full tracker by Eclipse

Our coverage of Eclipse

cloud

Total eclipse of the Internet: traffic impacts in Iceland, Spain, and Portugal

Cloudflare's data shows a clear impact on Internet traffic from Iceland to Spain and Portugal, following the path of totality of the total solar eclipse that occurred on August 12, 2026.

zero-day

Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’

Dropped on Patch Tuesday, the exploit allows any user to spawn a shell with System privileges. The post Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’ appeared first on SecurityWeek.