Multiple Vulnerabilities in Ubuntu 18.04 LTS Require Immediate Attention

Multiple Vulnerabilities in Ubuntu 18.04 LTS Require Immediate Attention

First seen 23 Jul 2026, 14:24 UTC Ubuntu 72% similarity 72.0

Article Content

Browse articles
ThreatCluster

On July 23, 2026, Ubuntu released updates for two critical vulnerabilities affecting Ubuntu 18.04 LTS. The first, USN-8369-2, addresses a regression in mod_jk related to CVE-2023-41081, which allows local attackers to potentially view or modify sensitive configuration data. The second, USN-8322-2, reintroduces fixes for CVE-2014-0114 and CVE-2019-10086 in Apache Commons BeanUtils, which could allow attackers to execute arbitrary code. Both vulnerabilities were previously fixed but had their patches dropped during update preparation. Users are advised to update their systems to mitigate these risks. The vulnerabilities could lead to sensitive information exposure and denial of service for mod_jk, while BeanUtils could allow for remote code execution. The updates are critical for maintaining system security and integrity.

Key Points: • Ubuntu 18.04 LTS users must update to fix dropped patches for critical vulnerabilities. • CVE-2023-41081 affects mod_jk, allowing local attackers to access sensitive data. • CVE-2014-0114 and CVE-2019-10086 in Apache Commons BeanUtils could enable remote code execution.

ThreatCluster AI

Timeline

2014-04-30
CVE-2014-0114 published
A vulnerability in Apache Commons BeanUtils was disclosed, allowing unauthorized access to Java enum properties.
Ubuntu
2019-08-20
CVE-2019-10086 published
A vulnerability in Apache Commons BeanUtils was disclosed, enabling potential arbitrary code execution.
Ubuntu
2023-09-13
CVE-2023-41081 published
A vulnerability in Apache Tomcat Connectors was disclosed, affecting shared memory permissions.
Ubuntu
2026-07-23
USN-8369-2 released
Ubuntu reintroduced the fix for CVE-2023-41081 after it was dropped in a previous update.
Ubuntu
2026-07-23
USN-8322-2 released
Ubuntu reintroduced fixes for CVE-2014-0114 and CVE-2019-10086 after they were dropped.
Ubuntu

Community

Browse all →