PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Network Vulnerabilities·Updated Aug 2, 2026

Apache HertzBeat < 1.6.0 - SnakeYAML Deserialization Remote Code Execution

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsdomain, subdomain, ipv4
CostFree
3.2k
Times Used
continuous scan runs
0
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-42323
8.8
CVSShigh
Exploitable remotely over the internet · low-privilege account sufficient.

SnakeYaml Deser Load Malicious xml rce vulnerability in Apache HertzBeat (incubating).  This vulnerability can only be exploited by authorized attackers. This issue affects Apache HertzBeat (incubating): before 1.6.0. Users are recommended to upgrade to version 1.6.0, which fixes the issue.

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
Apache HertzBeatby Apache Software Foundation
AFFECTED< 1.6.0SAFE ✓≥ 1.6.0
hertzbeatby apache
AFFECTED< 1.6.0SAFE ✓≥ 1.6.0
Updated Sep 9, 2026View on NVD →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.