Apereo CAS RCE flaw patched in 7.3.8.3
ANSSI advisory warns of a remote code execution vulnerability in Apereo CAS versions before 7.3.8.3.
The French national cybersecurity agency (ANSSI/CERT-FR) published an advisory regarding a vulnerability in Apereo CAS (Central Authentication Service), a widely used open-source single sign-on solution. The flaw affects CAS versions 7.3.x prior to 7.3.8.3 and allows an attacker to achieve remote code execution.
No details on exploitation in the wild are provided in the advisory, and no CVE identifier is referenced in the bulletin text. Defenders running Apereo CAS should consult the vendor's security bulletin published September 8, 2026, and upgrade to version 7.3.8.3 or later to remediate the vulnerability. Given that CAS is often deployed as a central authentication gateway for enterprise and institutional environments, successful exploitation could have significant downstream impact on identity and access management infrastructure.
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1150
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free