logo

CVE-2026-23918: Critical Apache HTTP/2 Flaw Can Trigger DoS and Possible RCE

ID: a4fc0998-a720-52d4-9b98-34f16bd938e0

STIX ID: report--a4fc0998-a720-52d4-9b98-34f16bd938e0

Feed Name: SOC Prime Blog

Threat Score
70/100

Date Published: 2026-05-06

Date Updated: 2026-05-06

Author: SOC Prime Team

...
...

Apache patched CVE-2026-23918, a critical double-free in mod_http2 (affecting Apache HTTP Server 2.4.66) that can crash worker processes and, under specific environment-dependent conditions, enable remote code execution; administrators should upgrade to 2.4.67 and prioritize externally reachable HTTP/2-enabled threaded MPM deployments or temporarily reduce HTTP/2 exposure until patched.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.