TL;DR
The Apache Software Foundation disclosed eight CVEs on October 2, 2026, across three projects. The most urgent is an Apache OpenOffice vulnerability, CVE-2026-59265, that runs attacker code when a user opens a crafted document. Its fix, version 4.1.17, is still a release candidate, while patches for Apache Directory LDAP API and Traffic Server are out now.
- Total: 8 CVEs
- Severity: 1 Critical · 1 High · 6 Unrated
- Actively exploited: None confirmed
- Highest severity: 9.3 (Critical · CVSSv3) — CVE-2026-102795
- Action: Apply the latest security updates now
Track every Apache CVE the moment it's exploited.
Get free email alertsNotable CVEs
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-102795 | 9.3 | SNI to Host header matching policy is not properly enforced | — | Not exploited |
| CVE-2026-103552 | 7.3 | CWE-121 | 1.2.9 | Not exploited |
| CVE-2026-59265 | Awaiting analysis | CWE-426 | 95923fd437e06edd38a4f0e139a27c755a6f3ba6, 181421139242694b309751fb666406eddc203c50 | Not exploited |
| CVE-2026-103877 | Awaiting analysis | CWE-502 | 2.1.9 | Not exploited |
| CVE-2026-102731 | Awaiting analysis | CWE-789 | 1.2.9 | Not exploited |
| CVE-2026-103878 | Awaiting analysis | CWE-345 | 2.1.9 | Not exploited |
| CVE-2026-103880 | Awaiting analysis | CWE-405 | 2.1.9 | Not exploited |
| CVE-2026-103885 | Awaiting analysis | Denial of service via crafted telephone number values | 2.1.9 | Not exploited |
Why It Matters
OpenOffice users have no finished patch yet, so a single malicious file could compromise a desktop. Meanwhile, the Apache Directory LDAP API ships inside LDAP servers such as Apache DS and inside Java apps that talk to directories. Its flaws let a rogue server or an unauthenticated client crash or hijack those systems.
No exploitation in the wild or public proof-of-concept has been confirmed for any of the eight flaws. Apache does not publish install counts for these projects.
How the Attacks Work
Apache OpenOffice
CVE-2026-59265 sits in the Java integration. NVD classifies it as an untrusted search path weakness (CWE-426). According to Apache, it “allows a crafted untrusted document to trigger executing arbitrary (even remote) code when opened by the user.”
Apache Directory LDAP API
Six CVEs hit the LDAP API. The most serious, CVE-2026-103877, is a deserialization bug. A rogue server or a pre-TLS attacker can answer a schema request with a serialized Java class, “allowing some potential RCE.”
Next, CVE-2026-103552 (CVSS 7.3) lets an unauthenticated client overflow the server’s stack with a deeply nested search filter. CVE-2026-102731 tricks the client into a huge memory allocation. Two more bugs pin a CPU core through crafted telephone numbers or bcrypt hashes with a very high cost. Finally, CVE-2026-103878 can leak plain-text data during a StartTLS upgrade.
Apache Traffic Server
CVE-2026-102795 is an improper access control flaw rated 7.0 on CVSS 4.0. It supersedes CVE-2026-41920, which listed the wrong 9.x version range. That earlier record named 9.1.15 as the fix. In fact, every 9.2.x release before 9.2.15 is also affected, so admins who trusted the old record may still be exposed.
Affected Versions
- Apache OpenOffice 4.1.16 and earlier
- Apache Directory LDAP API 2.1.0 before 2.1.9 (four CVEs) and 1.2.0 before 1.2.9 (two CVEs)
- Apache Traffic Server 9.0.0 through 9.2.14 and 10.0.0 through 10.1.3
Patch and Mitigation Steps
For the Apache OpenOffice vulnerability, disable Java runtime integration in the Preferences dialog now. Apache says this “prevents the attack.” In addition, avoid opening untrusted files. Then install 4.1.17 from the Apache OpenOffice download page once it ships.
Next, upgrade to LDAP API 2.1.9 or 1.2.9 from the Apache Directory LDAP API downloads. Lastly, move Traffic Server to 9.2.15 or 10.1.4 via the Apache Traffic Server downloads page.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!