Actively exploited
Listed in CISA’s Known Exploited Vulnerabilities catalog since December 1, 2021.
CVE-2021-40438
Apache HTTP Server-Side Request Forgery (SSRF) vulnerability
Added to KEV December 1, 2021
Alert details
- Source feed
- CISA KEV
- CVE ID
- CVE-2021-40438
- CWE
- CWE-918
- Affected products
- Apache · Apache Apache
What happened
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
What it means for your business
Apache Apache is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-40438). A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. CISA remediation due date: 2021-12-15. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Required action
Apply updates per vendor instructions.
CISA due date: December 15, 2021
Sources
Related briefs
Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
Apache Tomcat is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-34486). Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. CISA remediation due date: 2026-08-07. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows PowerShell Remote Code Execution vulnerability
Windows PowerShell Remote Code Execution vulnerability (CVE-2026-40400) was added to Microsoft’s security update guidance. Acknowledgement Updated PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Progress LoadMaster Command Injection Vulnerability
Progress LoadMaster is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-8037). Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints. CISA remediation due date: 2026-08-10. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Azure Active Directory Elevation of Privilege vulnerability
Azure Active Directory Elevation of Privilege vulnerability (CVE-2026-50481) was added to Microsoft’s security update guidance. Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Need help patching?
PremierePC monitors KEV alerts for managed clients and helps teams prioritize remediation before attackers do.