Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Apache Patches Critical Vulnerabilities in HTTP Server

Apache Patches Critical Vulnerabilities in HTTP Server

Posted on May 5, 2026 By CWS

Apache has released new security patches addressing critical and high-severity vulnerabilities in its HTTP Server and MINA project. These updates, announced on Monday, fix issues that could potentially allow remote code execution (RCE).

Details of the Apache HTTP Server Patch

The latest version, Apache HTTP Server 2.4.67, includes fixes for 11 security flaws. Notably, 10 of these vulnerabilities affect all previous versions of the software. Among these is CVE-2026-23918, a critical double-free and possible RCE vulnerability within the HTTP/2 protocol. Attackers could exploit this flaw by initiating an early reset, potentially leading to a denial-of-service (DoS) attack and arbitrary code execution.

Another significant issue addressed is CVE-2026-28780, which is a heap buffer overflow vulnerability. This flaw allows remote attackers to craft AJP messages to cause a DoS condition and execute malicious code. Additionally, three other vulnerabilities, identified as CVE-2026-29168, CVE-2026-29169, and CVE-2026-33007, pose risks of DoS attacks.

Information Disclosure and Security Weaknesses

The update also mitigates several vulnerabilities that could lead to information disclosure, including CVE-2026-24072, CVE-2026-33857, CVE-2026-34032, and CVE-2026-34059. Furthermore, CVE-2026-33523, a CRLF sequence neutralization issue, allows attackers to manipulate HTTP responses. Another critical patch addresses a timing side-channel weakness, tracked as CVE-2026-33006, which could facilitate Digest authentication bypass.

Apache MINA Updates

In addition to HTTP Server updates, Apache has rolled out MINA 2.2.7 and MINA 2.1.12. These versions rectify two critical vulnerabilities, which include CVE-2026-42778 and CVE-2026-42779. The former is an incomplete fix for previous deserialization vulnerabilities, while the latter addresses an improper check flaw, both of which could lead to RCE.

Apache advises organizations to explicitly configure their systems to accept only trusted classes in the ObjectSerializationDecoder instance following these updates, ensuring enhanced security.

As vulnerabilities continue to emerge, these updates are crucial for maintaining the integrity and security of systems relying on Apache’s software. Organizations are strongly urged to apply these patches immediately to safeguard against potential exploits.

Security Week News Tags:Apache, bug fixes, CVE, Cybersecurity, HTTP Server, MINA, Patches, remote code execution, security update, software update, Vulnerabilities

Post navigation

Previous Post: AI Service Security Risks: A Deep Dive into Exposed Systems
Next Post: WhatsApp Flaw Exploited via Instagram Reels Integration

Related Posts

Mainline Health, Select Medical Each Disclose Data Breaches Impacting 100,000 People Mainline Health, Select Medical Each Disclose Data Breaches Impacting 100,000 People Security Week News
Data Breach at Texas Parks Affects Millions Data Breach at Texas Parks Affects Millions Security Week News
CISO Burnout – Epidemic, Endemic, or Simply Inevitable? CISO Burnout – Epidemic, Endemic, or Simply Inevitable? Security Week News
Chrome, Firefox Updates Resolve High-Severity Memory Bugs Chrome, Firefox Updates Resolve High-Severity Memory Bugs Security Week News
Red Teams Jailbreak GPT-5 With Ease, Warn It’s ‘Nearly Unusable’ for Enterprise Red Teams Jailbreak GPT-5 With Ease, Warn It’s ‘Nearly Unusable’ for Enterprise Security Week News
Cisco Addresses Critical Flaw in Secure Workload Cisco Addresses Critical Flaw in Secure Workload Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Feral Wolf Ransomware Exploits Exposed Business Systems
  • Abandoned CDN Domain Re-Registered, Impacting Thousands
  • Microsoft Patches Severe Azure AI Foundry Vulnerability
  • Brevo Security Breach Impacts Over 100,000 Websites
  • Transparent Tribe Unveils New Rust Backdoor Strategy

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Feral Wolf Ransomware Exploits Exposed Business Systems
  • Abandoned CDN Domain Re-Registered, Impacting Thousands
  • Microsoft Patches Severe Azure AI Foundry Vulnerability
  • Brevo Security Breach Impacts Over 100,000 Websites
  • Transparent Tribe Unveils New Rust Backdoor Strategy

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark