CVE-2026-33523: exploitation status and patch state
CVE-2026-33523 · CVSS 6.5 MEDIUM · EPSS <1% · patch available
HTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compromised backend servers.
This issue affects Apache HTTP Server: from through 2.4.66.
Users are recommended to upgrade to version 2.4.67, which fixes the issue.
Is CVE-2026-33523 exploited?
Not in the CISA KEV catalog.
EPSS puts exploitation in the next 30 days at <1%.
Public exploit code: none found in monitored sources.