Vulnerabilities & Exploits
The real issue is not a single Apache bug. Apache HTTP Server 2.4.66 and earlier carry multiple flaws across different modules, so exposure depends on what each host actually has enabled. The most serious is a pre-authentication HTTP/2 double-free that can allow code execution.
NCSC-NL’s advisory confirms the fixed release is Apache HTTP Server 2.4.67 and lists module-specific failures in mod_proxy_ajp, mod_md, mod_dav_lock, mod_auth_digest, and mod_authn_socache, plus core-server parsing issues. The advisory also calls out .htaccess-based privilege escalation and HTTP response splitting, which broadens the blast radius beyond the headline HTTP/2 issue.
For operators, the remediation scope is the point: a binary upgrade alone does not tell you which hosts were exposed to which flaw. The fleet needs module-by-module verification because different Apache features fail in different ways, from crashes to auth bypass to code execution.
1 source · May 6
CVEs in this update
11 CVEs
Across DevOps Code ClearCase, Secure Connect Gateway, Rational ClearCase, and related packages.
0 critical · 5 high · 5 medium · 0 low
0 in CISA KEV · 0 with EPSS above 1%
Highest severity: CVE-2026-23918 · 8.8 HIGH
Highest EPSS: CVE-2026-33006 · 0.56%
Showing the top 10 by KEV, EPSS, and severity.
NCSC-NL Advisories
Beveiligingsadviezen
NCSC NL | Beveiligingsadviezen
originalPart of the PlainSec briefing for 2026-05-07
Every edition of this story: Apache Patch Hides Module-Specific Exposure Across Hosts