Linuxsecurity Oracle Linux 9 Vulnerabilities Lead to Critical Security Advisories
Article Content
- •Oracle Linux 9 has critical vulnerabilities affecting Apache HTTP Server and mod_http2.
- •CVE-2026-28780 enables arbitrary code execution, posing a severe threat to affected systems.
- •Immediate patching is necessary to prevent potential service disruptions and unauthorized access.
Oracle Linux 9 has issued two important advisories addressing critical vulnerabilities in the Apache HTTP Server. The first advisory (ELSA-2026-21391) details multiple CVEs, including CVE-2026-28780, which allows arbitrary code execution via a heap-based buffer overflow. Other vulnerabilities include CVE-2026-33007, a NULL pointer dereference, and CVE-2026-34059, which involves memory disclosure. The second advisory (ELSA-2026-25057) focuses on mod_http2, which is susceptible to a remote Denial of Service (DoS) attack via a compression bomb (CVE-2026-49975). Both advisories affect Oracle Linux 9 and require immediate attention from system administrators to mitigate risks. The vulnerabilities could potentially lead to service disruptions and unauthorized access if not patched promptly.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track CVE-2025-53020 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…