Skip to main content
x

High Severity Vulnerability in Apache HTTP Server

Apache Software Foundation has released security updates to address a high severity vulnerability in the Apache HTTP Server. Users and administrators of the affected product are advised to update to the latest version immediately.

Background

Apache Software Foundation has released security updates to address a high severity vulnerability (CVE-2026-23918) in the Apache HTTP Server with the HTTP/2 protocol. The vulnerability has a Common Vulnerability Scoring System (CVSS v3.1) score of 8.8 out of 10.

Impact

Successful exploitation of the Double Free and possible Remote Code Execution (RCE) vulnerability could allow a remote unauthenticated attacker to crash Apache HTTP Server processes, resulting in a denial‑of‑service attack, or under certain conditions, execute arbitrary code on the affected system.

Affected Products

This vulnerability affects Apache HTTP Server 2.4.66.

Recommendations

Users and administrators of the affected product are advised to update to the latest version immediately.

 

References

https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-049/