CVE-2026-15555 – Red Hat JBoss Enterprise Application Platform 7.4.25

CVSS 8.8 IMPORTANT Critical - Same Day Deployment

“Authentication bypass and unsafe server processing can expose protected applications to impersonation, code execution, and service disruption.”

Red Hat JBoss Enterprise Application Platform 7.4.25 is affected by ten vulnerabilities spanning authentication bypass, unsafe deserialization, remote class loading, privilege escalation, and denial of service. CVE-2026-10579 has a CVSS score of 9.8, Critical severity and can allow an unauthenticated attacker to forge SAML assertions and authenticate as arbitrary users with arbitrary roles. CVE-2026-15555 has a CVSS score of 8.8, High severity and can enable remote code execution through unsafe session-data deserialization.

The remaining High-severity vulnerabilities have CVSS scores from 7.4 to 8.1 and include additional SAML authentication bypass, remote class loading, forged certificate authentication, unauthenticated JNDI manipulation, and multiple remotely triggered denial-of-service conditions.

Key Details

Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-502
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.