Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
Oracle Linux 9 has issued two important advisories addressing critical vulnerabilities in the Apache HTTP Server. The first advisory (ELSA-2026-21391) details multiple CVEs, including CVE-2026-28780, which allows arbitrary code execution via a heap-based buffer overflow. Other vulnerabilities includ...
SUSE and openSUSE have released important updates for Apache2 addressing a total of 66 vulnerabilities, including critical issues like CVE-2026-23918, a potential remote code execution (RCE) vulnerability. The updates affect various modules such as mod_rewrite, mod_proxy_ajp, and mod_ldap, with seve...
A regression in Apache HTTP Server was introduced by USN-8571-1, which failed to fully address vulnerabilities, leading to potential denial of service when HTTP/2 proxying is enabled. The vulnerabilities include CVE-2026-33007, which allows remote attackers to exploit memory operations, and CVE-2026...