SUSE and openSUSE Apache2 Updates Address Multiple Vulnerabilities

SUSE and openSUSE Apache2 Updates Address Multiple Vulnerabilities

First seen 30 Jun 2026, 17:15 UTC Linuxsecurity 91% similarity 70.5
Share:

Article Content

Browse articles
ThreatCluster

SUSE and openSUSE have released important updates for Apache2 addressing a total of 66 vulnerabilities, including critical issues like CVE-2026-23918, a potential remote code execution (RCE) vulnerability. The updates affect various modules such as mod_rewrite, mod_proxy_ajp, and mod_ldap, with several vulnerabilities allowing privilege escalation, server crashes, and denial of service. Notably, CVE-2026-24072 and CVE-2026-33006 have proof-of-concept (PoC) exploits available, increasing the urgency for patching. The updates were released on June 29, 2026, and are crucial for maintaining the security of affected systems. Users are advised to apply the patches immediately to mitigate risks associated with these vulnerabilities.

Key Points: • SUSE and openSUSE updates fix 66 vulnerabilities in Apache2, including critical RCE risks. • CVE-2026-23918 and CVE-2026-24072 have public PoCs, heightening the urgency for patching. • Affected modules include mod_rewrite, mod_proxy_ajp, and mod_ldap, with various attack vectors.

ThreatCluster AI

Timeline

2026-05-04
Multiple CVEs published
CVE-2026-23918, CVE-2026-24072, and others were disclosed, exposing significant vulnerabilities in Apache2.
Linuxsecurity
2026-05-04
CVE-2026-29169 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-04
CVE-2026-33006 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-04
CVE-2026-33007 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-04
CVE-2026-33857 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-04
CVE-2026-24072 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-04
CVE-2026-34032 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-04
CVE-2026-33523 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-05
First PoC for CVE-2026-23918 released
Public proof-of-concept exploit for CVE-2026-23918, a critical RCE vulnerability, was made available.
Linuxsecurity
2026-05-05
CVE-2026-29168 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

Community

Browse all →