Rewterz
Iran-Linked Hackers Target U.S. Critical Infrastructure – Active IOCs
March 10, 2026
Rewterz
NJRAT – Active IOCs
March 11, 2026

Multiple Apache Ranger Vulnerabilities

Severity

High

Analysis Summary

CVE-2025-59060 CVSS:5.3

Apache Ranger could allow a remote attacker to bypass hostname verification, caused by a hostname verification bypass issue in Apache Ranger NiFiRegistryClient/NiFiClient. This allows an attacker to bypass intended hostname verification.

CVE-2025-59059 CVSS:9.8

Apache Ranger could allow a remote attacker to execute arbitrary code on the system, caused by a remote code execution Vulnerability in NashornScriptEngineCreator.

Impact

  • Security Bypass
  • Code Execution

Indicators of Compromise

CVE

  • CVE-2025-59060

  • CVE-2025-59059

Affected Vendors

Apache

Affected Products

  • Apache Software Foundation Apache Ranger 2.7.0
  • Apache Ranger 2.7.0

Remediation

Upgrade to the latest version, available from the Apache Website.

CVE-2025-59060

CVE-2025-59059