CERT-FR warns of Apache ZooKeeper flaws
Multiple vulnerabilities in Apache ZooKeeper 3.8.x before 3.8.7 and 3.9.x before 3.9.6 allow data confidentiality/integrity breaches and security bypass.
CERT-FR has issued an advisory covering five vulnerabilities affecting Apache ZooKeeper, a widely used distributed coordination service for distributed applications. The affected versions are ZooKeeper 3.8.x prior to 3.8.7 and 3.9.x prior to 3.9.6. Successful exploitation could allow an attacker to compromise data confidentiality, compromise data integrity, and bypass security policy enforcement mechanisms.
No indication of active exploitation in the wild is provided in this advisory. CERT-FR directs administrators to the Apache ZooKeeper security bulletin dated September 16, 2026 for patches and further details. Defenders running ZooKeeper should identify all deployed instances, confirm version numbers against the affected ranges, and prioritize upgrading to 3.8.7, 3.9.6, or later as appropriate. Given ZooKeeper's role in coordinating distributed systems (often underpinning Kafka, Hadoop, and other big-data/infrastructure stacks), unpatched instances could expose broader downstream services to risk.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1177
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free