Gallery

Contacts

411 University St, Seattle, USA

engitech@oceanthemes.net

+1 -800-456-478-23

CVE-2026-43870 is a critical vulnerability (CVSS 9.4) in the Apache Thrift Node.js web_server.js component as shipped in Microsoft CBL-Mariner 2.0, disclosed during Microsoft Patch Tuesday May 2026. Organizations running CBL-Mariner 2.0 with the ceph 16.2.10-11 package are exposed to potential remote attack via a network-accessible RPC interface. No active exploitation has been confirmed, but the critical severity warrants prompt patching, as exploitation tooling historically emerges within 1-4 weeks of public disclosure for CVEs of this rating.

Author

Tech Jacks Solutions