Critical Vulnerability in HTTP-Daemon Affects Multiple Ubuntu Releases

Critical Vulnerability in HTTP-Daemon Affects Multiple Ubuntu Releases

First seen 10 Jun 2026, 19:32 UTC UbuntuLinuxsecurity 80% similarity 74.0

Article Content

Browse articles
ThreatCluster

A security vulnerability has been identified in the HTTP-Daemon affecting various Ubuntu versions, including 26.04 LTS and earlier releases down to 14.04 LTS. The flaw allows remote attackers to execute arbitrary commands, create or overwrite files, and potentially expose sensitive information through specially crafted network traffic. This issue arises from improper handling of untrusted input by the HTTP-Daemon. Users are advised to update to the latest package versions to mitigate the risk. The vulnerability has been assigned Ubuntu Security Notice USN-8419-1. Affected packages include libhttp-daemon-perl across multiple Ubuntu releases. Standard system updates will apply the necessary fixes. Ubuntu Pro users have additional support for older versions.

Key Points: • HTTP-Daemon vulnerability allows remote command execution on affected Ubuntu systems. • Multiple Ubuntu versions from 14.04 LTS to 26.04 LTS are impacted. • Users are urged to update their systems to the latest package versions immediately.

ThreatCluster AI

Timeline

2026-06-10
Security vulnerability disclosed
Ubuntu announced a critical vulnerability in HTTP-Daemon affecting multiple releases, allowing remote command execution.
Linuxsecurity
2026-06-10
Patch available for affected systems
Ubuntu provided updated package versions to address the HTTP-Daemon vulnerability across all affected releases.
Ubuntu

Community

Browse all →

Tracked Entities in This Story