VORANT. Threat Intelligence Sign in Get the full feed

CERT-FR warns of Apache ZooKeeper flaws

routine vulnerability technologyinfrastructure

Multiple vulnerabilities in Apache ZooKeeper 3.8.x before 3.8.7 and 3.9.x before 3.9.6 allow data confidentiality/integrity breaches and security bypass.

CERT-FR has issued an advisory covering five vulnerabilities affecting Apache ZooKeeper, a widely used distributed coordination service for distributed applications. The affected versions are ZooKeeper 3.8.x prior to 3.8.7 and 3.9.x prior to 3.9.6. Successful exploitation could allow an attacker to compromise data confidentiality, compromise data integrity, and bypass security policy enforcement mechanisms.

No indication of active exploitation in the wild is provided in this advisory. CERT-FR directs administrators to the Apache ZooKeeper security bulletin dated September 16, 2026 for patches and further details. Defenders running ZooKeeper should identify all deployed instances, confirm version numbers against the affected ranges, and prioritize upgrading to 3.8.7, 3.9.6, or later as appropriate. Given ZooKeeper's role in coordinating distributed systems (often underpinning Kafka, Hadoop, and other big-data/infrastructure stacks), unpatched instances could expose broader downstream services to risk.

Mentioned in this report

Vulnerabilities CVE-2026-59739CVE-2026-59969CVE-2026-79993CVE-2026-84439CVE-2026-84501

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1177

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free