Skip to main content
All vendors

Apache security briefs

52 published alerts for Apache products and services.

Microsoft MSRC

CVE-2026-43871

Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byte-count limit vulnerability

Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byte-count limit vulnerability (CVE-2026-43871) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2025-49506

Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack vulnerability

Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack vulnerability (CVE-2025-49506) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-34486

Apache Tomcat Missing Encryption of Sensitive Data Vulnerability

Apache Tomcat is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-34486). Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813. CISA remediation due date: 2026-08-07. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-48913

Apache HTTP Server: mod_http2 memory corruption when file handles exhausted vulnerability

Apache HTTP Server: mod_http2 memory corruption when file handles exhausted vulnerability (CVE-2026-48913) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-44631

Apache HTTP Server: Heap Underflow in `ap_regname` via Signed Char Overflow

Apache Apache HTTP Server: Heap Underflow in `ap_regname` via Signed Char Overflow (CVE-2026-44631) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-44186

Apache HTTP Server: Loop in `proxy_ftp_handler` in mod_proxy_ftp

Apache Apache HTTP Server: Loop in `proxy_ftp_handler` in mod_proxy_ftp (CVE-2026-44186) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-44185

Apache HTTP Server: Stack Buffer Over-Read in mod_ssl OCSP `send_request`

Apache Apache HTTP Server: Stack Buffer Over-Read in mod_ssl OCSP `send_request` (CVE-2026-44185) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-44119

Apache HTTP Server: escalation of privilege through expressions in .htaccess in multiple modules

Apache Apache HTTP Server: escalation of privilege through expressions in .htaccess in multiple modules (CVE-2026-44119) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-43951

Apache HTTP Server: OOB Read in `merge_response_headers` can cause crash

Apache Apache HTTP Server: OOB Read in `merge_response_headers` can cause crash (CVE-2026-43951) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-42536

Apache HTTP Server: mod_xml2enc heap overflow vulnerability

Apache HTTP Server: mod_xml2enc heap overflow vulnerability (CVE-2026-42536) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-42535

Apache HTTP Server: mod_dav_fs protected directory access vulnerability

Apache HTTP Server: mod_dav_fs protected directory access vulnerability (CVE-2026-42535) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-34356

Apache HTTP Server: ProxyPassReverseCookieMap buffer overflow vulnerability

Apache HTTP Server: ProxyPassReverseCookieMap buffer overflow vulnerability (CVE-2026-34356) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-34355

Apache HTTP Server: mod_proxy_html buffer overflow vulnerability

Apache HTTP Server: mod_proxy_html buffer overflow vulnerability (CVE-2026-34355) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-29170

Apache HTTP Server: mod_proxy_ftp XSS vulnerability

Apache HTTP Server: mod_proxy_ftp XSS vulnerability (CVE-2026-29170) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-29167

Apache HTTP Server: mod_ldap per-dir use-after-free vulnerability

Apache HTTP Server: mod_ldap per-dir use-after-free vulnerability (CVE-2026-29167) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-49975

Apache HTTP Server: mod_http2 denial of service vulnerability

Apache HTTP Server: mod_http2 denial of service vulnerability (CVE-2026-49975) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-41607

Apache Thrift: C++ JSON OOB read vulnerability

Apache Thrift: C++ JSON OOB read vulnerability (CVE-2026-41607) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-41606

Apache Thrift: c_glib dispatch stack overflow vulnerability

Apache Thrift: c_glib dispatch stack overflow vulnerability (CVE-2026-41606) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-7262

SOAP apache:Map decoder with missing <value> vulnerability

SOAP apache:Map decoder with missing <value> vulnerability (CVE-2026-7262) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-6722

SOAP using Apache map vulnerability

SOAP using Apache map vulnerability (CVE-2026-6722) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-43870

Apache Thrift: Node.js web_server.js multi-vulnerability

Apache Thrift: Node.js web_server.js multi-vulnerability (CVE-2026-43870) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-43869

Apache Thrift: TSSLTransportFactory.java hostname verification vulnerability

Apache Thrift: TSSLTransportFactory.java hostname verification vulnerability (CVE-2026-43869) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-43868

Apache Thrift: Rust implementation vulnerable to CVE-2020-13949 pattern vulnerability

Apache Thrift: Rust implementation vulnerable to CVE-2020-13949 pattern vulnerability (CVE-2026-43868) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-41636

Apache Thrift: Node.js skip() recursion vulnerability

Apache Thrift: Node.js skip() recursion vulnerability (CVE-2026-41636) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.