Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Apache HTTP Server 2.4.68 Released to Fix Critical Vulnerabilities

Apache HTTP Server 2.4.68 Released to Fix Critical Vulnerabilities

Posted on June 9, 2026 By CWS

The Apache Software Foundation has announced the release of Apache HTTP Server version 2.4.68 on June 8, 2026. This latest update addresses 13 significant security vulnerabilities that impact various modules within the server. Administrators are strongly advised to update to this version to enhance security and functionality.

Critical Security Flaws Patched

This update resolves multiple security issues including use-after-free conditions, cross-site scripting (XSS), heap-based buffer overflows, denial-of-service (DoS) attacks, privilege escalation, and out-of-bounds read problems. These vulnerabilities affect all versions from 2.4.0 to 2.4.67, making the update essential for users on any prior version.

Details on Use-After-Free and XSS Issues

Two notable use-after-free vulnerabilities have been addressed. CVE-2026-29167 involves the mod_ldap module in per-directory configurations and was found across versions 2.4.0 to 2.4.67, reported by Pavel Kohout of Aisle Research. The second, CVE-2026-48913, affects the mod_http2 module, specifically when file handles are exhausted. This issue, reported by Sam Lovejoy of IBM X-Force Offensive Research (XOR), impacts versions 2.4.55 through 2.4.67.

An XSS vulnerability, CVE-2026-29170, was identified in the mod_proxy_ftp module, where unsanitized output can be exploited during FTP directory listings. This flaw affects all versions up to 2.4.67 and was discovered by Pavel Kohout.

Buffer Overflow and Denial-of-Service Vulnerabilities

Four buffer overflow issues have been corrected. These include CVE-2026-34355, a moderate severity buffer overflow in mod_proxy_html discovered by Elhanan Haenel and Junhui Lee, and CVE-2026-34356, a heap-based overflow in ProxyPassReverseCookieMap, identified by Arkadi Vainbrand and depthfirst.

Further, CVE-2026-42536, a heap overflow in mod_xml2enc, was reported by Zhenpeng (Leo) Lin of depthfirst. CVE-2026-44631, a heap underwrite vulnerability in ap_regname, was found by Lin and Bartlomiej Dmitruk.

Two notable DoS vulnerabilities were fixed. CVE-2026-49975, allowing memory exhaustion in mod_http2, was discovered by Quang Luong of Calif.IO in collaboration with OpenAI Codex. CVE-2026-44186 could trigger an infinite loop in mod_proxy_ftp, reported by attacker-controlled backend FTP server actions.

Recommendation and Future Updates

The Apache Software Foundation strongly advocates for an immediate upgrade to version 2.4.68, as no workarounds are available for most of these vulnerabilities. The updated version can be downloaded from the official Apache website.

For continued updates and information, users can follow the Apache Software Foundation on platforms such as Google News, LinkedIn, and X.

Cyber Security News Tags:Apache, buffer overflow, Cybersecurity, DoS, HTTP Server, Patch, security update, software release, use-after-free, Vulnerabilities, XSS

Post navigation

Previous Post: Google Releases Major Chrome Update Fixing 429 Vulnerabilities
Next Post: Critical FFmpeg Vulnerabilities Allow Remote Code Execution

Related Posts

1inch partners with Innerworks to strengthen DeFi security through AI-Powered threat detection 1inch partners with Innerworks to strengthen DeFi security through AI-Powered threat detection Cyber Security News
CISA Highlights Exploited Langflow Code Injection Flaw CISA Highlights Exploited Langflow Code Injection Flaw Cyber Security News
SideWinder Targets Government Emails with Fake PDF Viewer SideWinder Targets Government Emails with Fake PDF Viewer Cyber Security News
AtlasRAT Malware Hidden in Fake Flash Installer AtlasRAT Malware Hidden in Fake Flash Installer Cyber Security News
Authorities Seize BreachForums New Clearnet Cybercrime Marketplace Domain Authorities Seize BreachForums New Clearnet Cybercrime Marketplace Domain Cyber Security News
Bitter APT Hackers Exploit WinRAR Zero-Day Via Weaponized Word Documents to Steal Sensitive Data Bitter APT Hackers Exploit WinRAR Zero-Day Via Weaponized Word Documents to Steal Sensitive Data Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Innovative InjectEave Attack Eavesdrops on Headphones from 30 Meters
  • OpenAI Pledges $1 Billion for AI Cybersecurity Tools
  • New Linux Malware Tengu Hides as Kernel Process
  • ConnectWise Highlights ScreenConnect Security Issue
  • Microsoft Phasing Out Manifest V2 Extensions by 2027

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Innovative InjectEave Attack Eavesdrops on Headphones from 30 Meters
  • OpenAI Pledges $1 Billion for AI Cybersecurity Tools
  • New Linux Malware Tengu Hides as Kernel Process
  • ConnectWise Highlights ScreenConnect Security Issue
  • Microsoft Phasing Out Manifest V2 Extensions by 2027

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark