Enterprise Java platforms remain attractive targets because middleware often exposes paths developers assumed were internal. New research presented for Black Hat 2026 describes 12 flaws across products, including a sandbox escape and four pre-authentication issues. The serious findings are two remote code execution chains affecting Bonita BPM and Apache OFBiz. Both chains begin before login and rely on connections between routing, authentication code, and execution features. Researchers said every issue was responsibly reported through coordinated disclosure before publication. Administrators should apply updates, review exposed services, and avoid testing systems without authorization. Internal middleware must be treated as...
Read the full article at the source.
Comments (0)
No comments yet. Be the first to comment!