Apache security briefs
52 published alerts for Apache products and services.
Apache Thrift: Swift Compact Protocol integer overflow vulnerability
Apache Thrift: Swift Compact Protocol integer overflow vulnerability (CVE-2026-41605) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Apache Thrift: Java TSSLTransportFactory hostname verification vulnerability
Apache Thrift: Java TSSLTransportFactory hostname verification vulnerability (CVE-2026-41603) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Apache Thrift: Go TFramedTransport uint32 overflow vulnerability
Apache Thrift: Go TFramedTransport uint32 overflow vulnerability (CVE-2026-41602) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Apache Thrift: Specially crafted input can crash a c_glib Thrift server with invalid pointer error. vulnerability
Apache Thrift: Specially crafted input can crash a c_glib Thrift server with invalid pointer error. vulnerability (CVE-2025-48431) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Apache HTTP Server: mod_proxy_ajp: Heap Over-Read and memory disclosure in ajp_parse_data()
Apache Apache HTTP Server: mod_proxy_ajp: Heap Over-Read and memory disclosure in ajp_parse_data() (CVE-2026-34059) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Apache Apache HTTP Server: mod_proxy_ajp: Heap Buffer Over-Read Due to Missing Null-Termination Check (ajp_msg_get_string) vulnerability
Apache Apache HTTP Server: mod_proxy_ajp: Heap Buffer Over-Read Due to Missing Null-Termination Check (ajp_msg_get_string) vulnerability (CVE-2026-34032) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Apache HTTP Server: Off-by-one OOB reads in AJP getter functions
Apache Apache HTTP Server: Off-by-one OOB reads in AJP getter functions (CVE-2026-33857) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Apache HTTP Server: multiple modules: HTTP response splitting forwarding malicious status line vulnerability
Apache HTTP Server: multiple modules: HTTP response splitting forwarding malicious status line vulnerability (CVE-2026-33523) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Apache HTTP Server: mod_authn_socache crash vulnerability
Apache HTTP Server: mod_authn_socache crash vulnerability (CVE-2026-33007) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Apache HTTP Server: mod_auth_digest timing attack vulnerability
Apache HTTP Server: mod_auth_digest timing attack vulnerability (CVE-2026-33006) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Apache HTTP Server: mod_dav_lock indirect lock crash vulnerability
Apache HTTP Server: mod_dav_lock indirect lock crash vulnerability (CVE-2026-29169) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Apache HTTP Server: mod_md unrestricted OCSP response vulnerability
Apache HTTP Server: mod_md unrestricted OCSP response vulnerability (CVE-2026-29168) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Apache HTTP Server: mod_rewrite elevation of privileges via ap_expr vulnerability
Apache HTTP Server: mod_rewrite elevation of privileges via ap_expr vulnerability (CVE-2026-24072) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Apache HTTP Server: http2: double free and possible RCE on early reset vulnerability
Apache HTTP Server: http2: double free and possible RCE on early reset vulnerability (CVE-2026-23918) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Apache Thrift: Swift Range crash in skip()
Apache Apache Thrift: Swift Range crash in skip() (CVE-2026-41604) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
JsonTemplateLayout vulnerability
Apache Apache Log4j JSON Template Layout: Improper serialization of non-finite floating-point values in JsonTemplateLayout (CVE-2026-34481) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters
Apache Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters (CVE-2026-34480) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters vulnerability
Apache Apache Log4j 1 to Log4j 2 bridge: Silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters (CVE-2026-34479) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
TLS configuration vulnerability
Apache Apache Log4j Core: verifyHostName attribute silently ignored in TLS configuration, allowing hostname verification bypass (CVE-2026-34477) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Apache ActiveMQ Improper Input Validation Vulnerability
Apache ActiveMQ is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-34197). Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection. CISA remediation due date: 2026-04-30. If you need help checking exposure, call (864) 335-9223.
Apache ActiveMQ Deserialization of Untrusted Data Vulnerability
Apache ActiveMQ is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-46604). Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow a remote attacker with network access to a broker to run shell commands by manipulating serialized class types in the OpenWire protocol to cause the broker to instantiate any class on the classpath. CISA remediation due date: 2023-11-23. If you need help checking exposure, call (864) 335-9223.
Apache Log4j2 Deserialization of Untrusted Data Vulnerability
Apache Log4j2 is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-45046). Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations. CISA remediation due date: 2023-05-22. If you need help checking exposure, call (864) 335-9223.
Apache Tomcat on Windows Remote Code Execution Vulnerability
Apache Tomcat is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-12615). When running Apache Tomcat on Windows with HTTP PUTs enabled, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server. CISA remediation due date: 2022-04-15. If you need help checking exposure, call (864) 335-9223.
Apache Log4j2 Remote Code Execution Vulnerability
Apache Log4j2 is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-44228). Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution. CISA remediation due date: 2021-12-24. If you need help checking exposure, call (864) 335-9223.