Skip to main content

Actively exploited

Listed in CISA’s Known Exploited Vulnerabilities catalog since December 1, 2021.

Known ransomware use

CVE-2021-40438

Apache HTTP Server-Side Request Forgery (SSRF) vulnerability

Apache·Apache

Added to KEV December 1, 2021

Alert details

Source feed
CISA KEV
CVE ID
CVE-2021-40438
CWE
CWE-918
Affected products
Apache · Apache Apache

What happened

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.

What it means for your business

Apache Apache is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-40438). A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. CISA remediation due date: 2021-12-15. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Required action

Apply updates per vendor instructions.

CISA due date: December 15, 2021

Sources

Related briefs

Actively exploited (KEV)

CVE-2026-34486

Apache Tomcat Missing Encryption of Sensitive Data Vulnerability

Apache Tomcat is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-34486). Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. CISA remediation due date: 2026-08-07. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Apache·Tomcat

Actively exploited (KEV)

CVE-2026-18556

N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

N-able N-central is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-18556). N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass. CISA remediation due date: 2026-08-07. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

N-able·N-central

Industry news

Ongoing Threats of Swatting and Indicators for Community Members

Ongoing Threats of Swatting and Indicators for Community Members — FBI IC3 industry advisory relevant to cyber risk. PremierePC monitors federal alerts for Upstate SC businesses. Read the source link for full guidance or open a ticket if you want help assessing impact.

FBI IC3
Actively exploited (KEV)

CVE-2026-18577

N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

N-able N-central is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-18577). N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556. CISA remediation due date: 2026-08-06. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

N-able·N-central

Need help patching?

PremierePC monitors KEV alerts for managed clients and helps teams prioritize remediation before attackers do.