CVE-2021-39275: exploitation status and patch state
CVE-2021-39275 · CVSS 9.8 CRITICAL · EPSS 39%
ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but third-party / external modules may. This issue affects Apache HTTP Server 2.4.48 and earlier.
Is CVE-2021-39275 exploited?
Not in the CISA KEV catalog.
EPSS puts exploitation in the next 30 days at 39%.
Public exploit code: none found in monitored sources.