TL;DR
On October 1, the Apache Software Foundation released Apache HTTP Server 2.4.69 with fixes for 20 security flaws. Five rate moderate, led by a mod_vhost_alias stack overflow that may allow code execution. The rest rate low, and no attacks have been reported.
- Total: 20 CVEs
- Severity: 3 Critical · 13 High · 3 Medium · 1 Low
- Actively exploited: None confirmed
- Highest severity: 9.8 (Critical · CVSSv3) — CVE-2026-57941
- Action: Apply the latest security updates now
Too many Apache alerts in your inbox? Switch to one weekly digest, sorted by severity.
Try Team free for 14 daysNotable CVEs
| CVE | CVSS (CVSSv3) | Type | Status |
|---|---|---|---|
| CVE-2026-57941 | 9.8 | CWE-416 | Not exploited |
| CVE-2026-56154 | 9.8 | CWE-416 | Not exploited |
| CVE-2026-59797 | 9.8 | CWE-269 | Not exploited |
| CVE-2026-93546 | 8.8 | CWE-190 | Not exploited |
| CVE-2026-73636 | 8.1 | CWE-294 | Not exploited |
| CVE-2026-63292 | 7.5 | CWE-121 | Not exploited |
| CVE-2026-59685 | 7.5 | CWE-787 | Not exploited |
| CVE-2026-46729 | 7.5 | CWE-476 | Not exploited |
Why It Matters
Apache httpd runs a large share of the world’s web servers. So even moderate bugs deserve quick attention. Most of these flaws reach back to 2.4.0, which means nearly every 2.4 install is affected. The Apache advisory reports no exploitation in the wild and no public proof-of-concept.
How the Attacks Work
CVE-2026-63292: mod_vhost_alias Stack Overflow
This is the most serious bug. A remote client sends a Host header longer than 8192 bytes. The result can be “a denial of service or potentially execute arbitrary code,” the advisory says. However, it only works when VirtualDocumentRoot uses a hostname format and LimitRequestFieldSize sits above the default.
CVE-2026-57941: mod_http2 Use-After-Free
A re-entrancy bug in mod_http2 can lead to a use-after-free and a wild memory write. Since HTTP/2 is common, this one affects many busy sites. The advisory lists three separate teams as finders, which shows how many researchers now probe this module.
CVE-2026-59685: Windows Path Overflow
On Windows, short 8.3 file names can grow when the server expands them. That growth triggers an out-of-bounds write. The advisory limits this flaw to Windows builds.
WebDAV Crashes
Two more moderate flaws hit WebDAV. CVE-2026-42528 lets users who can create locks crash child processes. Meanwhile, CVE-2026-93546 lets writers corrupt a folder’s property database for good.
Low-Severity Fixes
The 15 low-rated bugs cover Digest auth replay and DoS, response smuggling in mod_proxy_uwsgi, and info leaks in mod_userdir and mod_dav_fs. One, CVE-2026-42356, allows limited code execution through CGI redirects. Still, the target file must already sit in a CGI-enabled folder.
Affected Versions
- Most flaws: Apache HTTP Server 2.4.0 through 2.4.68
- CVE-2026-42356: 2.4.60 through 2.4.68
Patch and Mitigation Steps
Admins should upgrade to Apache HTTP Server 2.4.69, as the Apache httpd 2.4 vulnerabilities page advises. Until then, take these steps:
- Keep LimitRequestFieldSize at its default if you use mod_vhost_alias.
- Disable unused modules such as mod_dav, mod_heartmonitor, and mod_proxy_ftp.
- Limit WebDAV write access to trusted users.
- Turn off Digest authentication if you no longer need it.
Also watch for updated packages from your Linux distribution, which often backport these fixes.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!