CVE-2026-33857: exploitation status and patch state
CVE-2026-33857 · CVSS 5.3 MEDIUM · patch available
Out-of-bounds Read vulnerability in mod_proxy_ajp of
Apache HTTP Server.
This issue affects Apache HTTP Server: through 2.4.66.
Users are recommended to upgrade to version 2.4.67, which fixes the issue.
Is CVE-2026-33857 exploited?
Not in the CISA KEV catalog.
Public exploit code: none found in monitored sources.