Skip to content
Critical Vulnerabilities in Apache HTTP Server and Ampache Exposed

Critical Vulnerabilities in Apache HTTP Server and Ampache Exposed

First seen 15 Sep 2026, 13:52 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 16, 2026 at 12:57 UTC
  • CVE-2021-42013 allows remote code execution in Apache HTTP Server 2.4.50.
  • Ampache versions prior to 4.4.3 are vulnerable to XSS attacks.
  • Proof-of-concept code is publicly available for both vulnerabilities.

Two significant vulnerabilities have been reported: CVE-2021-42013 in Apache HTTP Server and a cross-site scripting (XSS) vulnerability in Ampache. CVE-2021-42013 allows for remote code execution and path traversal, affecting Apache HTTP Server 2.4.50. The exploit can be executed using a crafted payload that accesses sensitive system files. Meanwhile, the Ampache vulnerability affects versions prior to 4.4.3, allowing for XSS attacks that can compromise user data. Both vulnerabilities have proof-of-concept code available, raising concerns about their exploitation in the wild. Organizations using these affected systems are advised to take immediate action to mitigate risks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2021-10-07
CVE-2021-42013 published
Apache HTTP Server 2.4.50 vulnerability disclosed, enabling remote code execution.
Sploitus
2021-10-08
First public PoC for CVE-2021-42013
Public proof-of-concept code for exploiting CVE-2021-42013 was released.
Sploitus
2021-11-03
CVE-2021-42013 added to CISA KEV
CISA confirmed active exploitation of CVE-2021-42013, advising immediate action.
Sploitus
2026-09-15
XSS vulnerability in Ampache reported
XSS vulnerability affecting Ampache versions before 4.4.3 disclosed, with PoC available.
Sploitus

More articles in this cluster (2)

Following this threat?

Track CVE-2021-42013 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed