CRITICAL 9.1 CVE-2026-55083 Published 1 Oct 2026

DHIS2 Remote Code Execution via Unsafe Java Deserialization

Worried this affects your website?

DHIS2, a flexible information system for data capture, management, validation, analytics and visualization, is vulnerable to remote code execution (RCE) via unsafe Java deserialization.

Affected versions:

  • 2.42.0 to before 2.42.5.1
  • 2.43.0 to before 2.43.0.1

This issue has been patched in versions 2.42.5.1, 2.43.0.1, and 2.44.

Reference: CVE-2026-55083 on NVD

← Back to Security News