Vulnerabilities & Exploits

Apache 2.4.69 Fixes Config-Dependent Flaws

The Apache Software Foundation released Apache HTTP Server 2.4.69 to fix 20 vulnerabilities in the 2.4.x line, including 3 critical and 13 high-severity issues. INCIBE-CERT and CSIRT Italia both said the affected range runs through 2.4.68.

Several of the bugs live only in specific modules or when particular directives are enabled. INCIBE-CERT says the critical flaws include use-after-free issues in mod_http2 and mod_rewrite, plus a mod_ssl privilege problem tied to .htaccess use, so the same version can be exposed on one server and not on another depending on local configuration.

For operators, the lasting point is that version numbers alone do not tell the whole exposure story. If Apache sits behind module-heavy deployments or allows .htaccess, the vulnerable surface depends on what is loaded and enabled, not just on the package version.

2 sources · 5h ago

CVE-2026-57941

NVD KEV

CVSS 9.8 CRITICAL: use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy This issue…

CVE-2026-56154

NVD KEV

CVSS 9.8 CRITICAL: use After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:...}) This…

CVE-2026-59797

NVD KEV

CVSS 9.8 CRITICAL: improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related…

Timeline

Sources

Part of the PlainSec briefing for 2026-10-02

Every edition of this story: Apache 2.4.69 Fixes Config-Dependent Flaws

More from today