Description:
The Apache Software Foundation released a security update to address multiple vulnerabilities in the HTTP Server and its modules. A remote attacker could exploit the vulnerabilities by sending a specially crafted request to the affected systems.
Affected Systems:
- Apache HTTP Server versions 2.4.0 prior to 2.4.69
For detailed information of the affected systems, please refer to the corresponding security advisory at software provider's website.
Impact:
Successful exploitation of the vulnerabilities could lead to remote code execution, denial of service, elevation of privilege, information disclosure, security restriction bypass, spoofing or tampering on an affected system.
Recommendation:
The Apache Software Foundation has released new version of the system to address the issues and they can be downloaded at the following URL:
https://httpd.apache.org/download.cgi
More Information:
- https://httpd.apache.org/download.cgi#apache24
- https://httpd.apache.org/security/vulnerabilities_24.html#2.4.69
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42356
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42528
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-46729
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-47360
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-48005
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56153 (to CVE-2026-56154)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56449
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-57941
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58415
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-59685
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-59797
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63045
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63292
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63686
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63718
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-73636 (to CVE-2026-73637)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-79768
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-93546