Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

CVE-2026-43870 is a critical vulnerability (CVSS 9.4) in the Apache Thrift Node.js web_server.js component as shipped in Microsoft CBL-Mariner 2.0, disclosed during Microsoft Patch Tuesday May 2026. Organizations running CBL-Mariner 2.0 with the ceph 16.2.10-11 package are exposed to potential remote attack via a network-accessible RPC interface. No active exploitation has been confirmed, but the critical severity warrants prompt patching, as exploitation tooling historically emerges within 1-4 weeks of public disclosure for CVEs of this rating.

Author

Tech Jacks Solutions