Vulnerabilities · 132 days ago

Apache Patch Hides Module-Specific Exposure Across Hosts

The real issue is not a single Apache bug. Apache HTTP Server 2.4.66 and earlier carry multiple flaws across different modules, so exposure depends on what each host actually has enabled. The most serious is a pre-authentication HTTP/2 double-free that can allow code execution.

NCSC-NL’s advisory confirms the fixed release is Apache HTTP Server 2.4.67 and lists module-specific failures in mod_proxy_ajp, mod_md, mod_dav_lock, mod_auth_digest, and mod_authn_socache, plus core-server parsing issues. The advisory also calls out .htaccess-based privilege escalation and HTTP response splitting, which broadens the blast radius beyond the headline HTTP/2 issue.

For operators, the remediation scope is the point: a binary upgrade alone does not tell you which hosts were exposed to which flaw. The fleet needs module-by-module verification because different Apache features fail in different ways, from crashes to auth bypass to code execution.

CVEs in this update

11 CVEs

Across DevOps Code ClearCase, Secure Connect Gateway, Rational ClearCase, and related packages.

0 critical · 5 high · 5 medium · 0 low

0 in CISA KEV · 0 with EPSS above 1%

Highest severity: CVE-2026-23918 · 8.8 HIGH

Highest EPSS: CVE-2026-33006 · 0.56%

Showing the top 10 by KEV, EPSS, and severity.

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-05-07

Editions

Related stories