Critical Apache HTTP Server Flaw Exposes Millions of Servers to RCE Attacks
ID: 3f89b3f7-c714-5a37-bc39-ec2f30f5e659
STIX ID: report--3f89b3f7-c714-5a37-bc39-ec2f30f5e659
Feed Name: cybersecurityNews.com
**Apache HTTP Server 2.4.67 released to address five vulnerabilities** — most critically CVE-2026-23918 (CVSS 8.8), a double-free in HTTP/2 in 2.4.66 enabling potential remote code execution; other fixes include a mod_rewrite privilege escalation (CVE-2026-24072), a mod_proxy_ajp heap overflow (CVE-2026-28780), an OCSP resource exhaustion issue in mod_md (CVE-2026-29168), and a mod_dav_lock NULL-pointer DoS (CVE-2026-29169). Administrators are advised to upgrade to 2.4.67 immediately, disable HTTP/2 if they cannot upgrade, remove mod_dav_lock if unused, and audit .htaccess permissions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
