Skip to content
Oracle Linux 9 Vulnerabilities Lead to Critical Security Advisories

Oracle Linux 9 Vulnerabilities Lead to Critical Security Advisories

First seen 25 Jun 2026, 07:24 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •June 26, 2026 at 06:40 UTC
  • •Oracle Linux 9 has critical vulnerabilities affecting Apache HTTP Server and mod_http2.
  • •CVE-2026-28780 enables arbitrary code execution, posing a severe threat to affected systems.
  • •Immediate patching is necessary to prevent potential service disruptions and unauthorized access.

Oracle Linux 9 has issued two important advisories addressing critical vulnerabilities in the Apache HTTP Server. The first advisory (ELSA-2026-21391) details multiple CVEs, including CVE-2026-28780, which allows arbitrary code execution via a heap-based buffer overflow. Other vulnerabilities include CVE-2026-33007, a NULL pointer dereference, and CVE-2026-34059, which involves memory disclosure. The second advisory (ELSA-2026-25057) focuses on mod_http2, which is susceptible to a remote Denial of Service (DoS) attack via a compression bomb (CVE-2026-49975). Both advisories affect Oracle Linux 9 and require immediate attention from system administrators to mitigate risks. The vulnerabilities could potentially lead to service disruptions and unauthorized access if not patched promptly.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 97d ago How this analysis works

Timeline

2025-07-10
CVE-2025-53020 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-04
Multiple CVEs published
CVE-2026-33007, CVE-2026-34059, CVE-2026-33857, and CVE-2026-34032 disclosed, affecting Apache HTTP Server.
Linuxsecurity
2026-05-04
CVE-2026-33007 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-04
CVE-2026-34059 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-04
CVE-2026-33857 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-04
CVE-2026-34032 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-05
CVE-2026-28780 published
Arbitrary code execution vulnerability in Apache HTTP Server disclosed, affecting Oracle Linux 9.
Linuxsecurity
2026-06-08
CVE-2026-49975 published
Remote DoS vulnerability in mod_http2 disclosed, impacting Oracle Linux 9 users.
Linuxsecurity
2026-06-25
Advisories released
Oracle Linux 9 issues advisories ELSA-2026-21391 and ELSA-2026-25057, urging immediate patching.
Linuxsecurity

More articles in this cluster (4)

Following this threat?

Track CVE-2025-53020 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed