
Enterprise Java Flaws Enable Pre-Auth RCE in Bonita BPM and Apache OFBiz
A newly disclosed 12 vulnerabilities affecting four enterprise Java platforms, including four pre-authentication flaws and a sandbox escape. Presented at Black Hat 2026, the research shows how overlooked middleware components, including routers, servlet dispatchers, SSO handlers, deserializers, and template engines, can combine to form complete remote code execution (RCE) chains. The most severe findings affect […]
The post Enterprise Java Flaws Enable Pre-Auth RCE in Bonita BPM and Apache OFBiz appeared first on Cyber Security News.