CVE-2026-24072: exploitation status and patch state

CVE-2026-24072 · CVSS 8.8 HIGH · patch available

An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user. Users are recommended to upgrade to version 2.4.67, which fixes this issue.

Is CVE-2026-24072 exploited?

Which products and versions are affected?

No affected package list recorded here yet.

Is there a patch?

What PlainSec published about CVE-2026-24072

Primary sources

What this record does not say

KEV and EPSS are re-checked daily. Record last updated 2026-08-11.