Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Apache Patches Critical Vulnerabilities in HTTP Server

Apache Patches Critical Vulnerabilities in HTTP Server

Posted on May 5, 2026 By CWS

Apache has released new security patches addressing critical and high-severity vulnerabilities in its HTTP Server and MINA project. These updates, announced on Monday, fix issues that could potentially allow remote code execution (RCE).

Details of the Apache HTTP Server Patch

The latest version, Apache HTTP Server 2.4.67, includes fixes for 11 security flaws. Notably, 10 of these vulnerabilities affect all previous versions of the software. Among these is CVE-2026-23918, a critical double-free and possible RCE vulnerability within the HTTP/2 protocol. Attackers could exploit this flaw by initiating an early reset, potentially leading to a denial-of-service (DoS) attack and arbitrary code execution.

Another significant issue addressed is CVE-2026-28780, which is a heap buffer overflow vulnerability. This flaw allows remote attackers to craft AJP messages to cause a DoS condition and execute malicious code. Additionally, three other vulnerabilities, identified as CVE-2026-29168, CVE-2026-29169, and CVE-2026-33007, pose risks of DoS attacks.

Information Disclosure and Security Weaknesses

The update also mitigates several vulnerabilities that could lead to information disclosure, including CVE-2026-24072, CVE-2026-33857, CVE-2026-34032, and CVE-2026-34059. Furthermore, CVE-2026-33523, a CRLF sequence neutralization issue, allows attackers to manipulate HTTP responses. Another critical patch addresses a timing side-channel weakness, tracked as CVE-2026-33006, which could facilitate Digest authentication bypass.

Apache MINA Updates

In addition to HTTP Server updates, Apache has rolled out MINA 2.2.7 and MINA 2.1.12. These versions rectify two critical vulnerabilities, which include CVE-2026-42778 and CVE-2026-42779. The former is an incomplete fix for previous deserialization vulnerabilities, while the latter addresses an improper check flaw, both of which could lead to RCE.

Apache advises organizations to explicitly configure their systems to accept only trusted classes in the ObjectSerializationDecoder instance following these updates, ensuring enhanced security.

As vulnerabilities continue to emerge, these updates are crucial for maintaining the integrity and security of systems relying on Apache’s software. Organizations are strongly urged to apply these patches immediately to safeguard against potential exploits.

Security Week News Tags:Apache, bug fixes, CVE, Cybersecurity, HTTP Server, MINA, Patches, remote code execution, security update, software update, Vulnerabilities

Post navigation

Previous Post: AI Service Security Risks: A Deep Dive into Exposed Systems
Next Post: WhatsApp Flaw Exploited via Instagram Reels Integration

Related Posts

Security Firm Andy Frain Says 100,000 People Impacted by Ransomware Attack Security Firm Andy Frain Says 100,000 People Impacted by Ransomware Attack Security Week News
Analysis of 6 Billion Passwords Shows Stagnant User Behavior Analysis of 6 Billion Passwords Shows Stagnant User Behavior Security Week News
TeamPCP Releases Source Code of Shai-Hulud Worm TeamPCP Releases Source Code of Shai-Hulud Worm Security Week News
Critical Vulnerability Puts 60,000 Redis Servers at Risk of Exploitation Critical Vulnerability Puts 60,000 Redis Servers at Risk of Exploitation Security Week News
Zyxel Firewall Vulnerability Again in Attacker Crosshairs Zyxel Firewall Vulnerability Again in Attacker Crosshairs Security Week News
The Loudest Voices in Security Often Have the Least to Lose The Loudest Voices in Security Often Have the Least to Lose Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CISA Urges Fortinet Device Security Amid FortiBleed Threat
  • Gentlemen RaaS Targets Security with EDR Framework
  • Rust-Based Ransomware Threatens Global Industries
  • Unpatchable usbliter8 Exploit Affects Apple Devices
  • Critical Flaw in Avada Plugin Threatens 1 Million Sites

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CISA Urges Fortinet Device Security Amid FortiBleed Threat
  • Gentlemen RaaS Targets Security with EDR Framework
  • Rust-Based Ransomware Threatens Global Industries
  • Unpatchable usbliter8 Exploit Affects Apple Devices
  • Critical Flaw in Avada Plugin Threatens 1 Million Sites

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark