# CERT-FR warns of Apache ZooKeeper flaws

Published: 2026-09-16 · Severity: routine · Sectors: technology, infrastructure
Canonical: https://vorant.io/reports/5a9fa681-777a-53b5-b713-dddab18849fa/cert-fr-warns-of-apache-zookeeper-flaws

> Multiple vulnerabilities in Apache ZooKeeper 3.8.x before 3.8.7 and 3.9.x before 3.9.6 allow data confidentiality/integrity breaches and security bypass.

CERT-FR has issued an advisory covering five vulnerabilities affecting Apache ZooKeeper, a widely used distributed coordination service for distributed applications. The affected versions are ZooKeeper 3.8.x prior to 3.8.7 and 3.9.x prior to 3.9.6. Successful exploitation could allow an attacker to compromise data confidentiality, compromise data integrity, and bypass security policy enforcement mechanisms.

No indication of active exploitation in the wild is provided in this advisory. CERT-FR directs administrators to the Apache ZooKeeper security bulletin dated September 16, 2026 for patches and further details. Defenders running ZooKeeper should identify all deployed instances, confirm version numbers against the affected ranges, and prioritize upgrading to 3.8.7, 3.9.6, or later as appropriate. Given ZooKeeper's role in coordinating distributed systems (often underpinning Kafka, Hadoop, and other big-data/infrastructure stacks), unpatched instances could expose broader downstream services to risk.

## Mentioned in this report

- Vulnerabilities: CVE-2026-59739, CVE-2026-59969, CVE-2026-79993, CVE-2026-84439, CVE-2026-84501

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1177

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/5a9fa681-777a-53b5-b713-dddab18849fa/cert-fr-warns-of-apache-zookeeper-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
