CVE-2026-107726Critical▾ MidnightHazelcast is a unified real-time data platform combining stream processing with a fast data store. Prior to 5.4.5, 5.5.10, and 5.6.1, improper validation of data supplied by a malicious client able to connect to a cluster allows arbitrar…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 52.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Hazelcast is a unified real-time data platform combining stream processing with a fast data store. Prior to 5.4.5, 5.5.10, and 5.6.1, improper validation of data supplied by a malicious client able to connect to a cluster allows arbitrary reads from a cluster member's Java heap, off-heap data, and JVM process address space. The same flaw can crash cluster members and, in some Hazelcast Enterprise Edition configurations, corrupt memory with possible arbitrary code execution. Both slim and full distributions are affected. This issue is fixed in versions 5.4.5, 5.5.10, 5.6.1, and 5.7.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
com.hazelcast:hazelcast = 5.6.0com.hazelcast:hazelcast >= 5.5.0, < 5.5.10com.hazelcast:hazelcast < 5.4.5Patched in:
com.hazelcast:hazelcast 5.7.0com.hazelcast:hazelcast 5.7.0com.hazelcast:hazelcast 5.7.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-107725HighHazelcast is a unified real-time data platform combining stream processing with a fast data store
CVE-2021-36325High· 7.5Dell BIOS contains an improper input validation vulnerability
CVE-2021-36323High· 7.5Dell BIOS contains an improper input validation vulnerability
CVE-2021-36324High· 7.5Dell BIOS contains an improper input validation vulnerability
CVE-2021-45105Medium· 5.9Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups
CVE-2020-3478High· 8.1A vulnerability in the REST API of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to overwrite certain files that should be restricted on an affected device