Api.Msrc.Microsoft Apache HTTP Server Vulnerabilities CVE-2024-47252 and CVE-2025-23048 Disclosed
Article Content
Browse articles
Two vulnerabilities in the Apache HTTP Server have been published: CVE-2024-47252, which involves mod_ssl error log variable escaping, and CVE-2025-23048, related to mod_ssl access control bypass with session resumption. Both vulnerabilities were published on July 10, 2025, affecting users of the Apache HTTP Server.
Ask AI about this cluster
Answers cite the sources they use
Updated 207d ago How this analysis works
Timeline
2025-07-10
CVE-2024-47252 and CVE-2025-23048 published
2025-10-22
First public PoC for CVE-2025-23048
More articles in this cluster (2)
Following this threat?
Track CVE-2024-47252 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…
Critical Zero-Day Exploits in Citrix NetScaler Confirmed by CISA On September 26, 2026, CISA confirmed the active exploitation of two critical zero-day vulnerabilities in Citrix NetScaler, identified as CVE-2026-88771 and CVE-2026-88772, both with a CVSS score of 9.5. These vulnerabilities allow remote code execution and affect all default configurations of NetScaler ADC and…