Actively exploited (KEV)Ransomware
Apache HTTP Server-Side Request Forgery (SSRF) vulnerability
Apache Apache is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-40438). A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. CISA remediation due date: 2021-12-15. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.