The Apache Software Foundation released Apache HTTP Server 2.4.68 to patch 13 vulnerabilities affecting versions prior to 2.4.68, with many issues spanning 2.4.0 through 2.4.67. The flaws span multiple modules, including mod_http2, mod_proxy_ftp, mod_proxy_html, mod_ssl, mod_ldap, mod_dav_fs, mod_xml2enc, and mod_headers, and include use-after-free, heap and buffer overflows, out-of-bounds reads, denial-of-service conditions, cross-site scripting, privilege-escalation and path-handling weaknesses. Apache and national defenders, including Canada’s Cyber Centre, urged administrators to review the advisory and upgrade because workarounds are unavailable for most of the issues.
Notable CVEs include CVE-2026-49975, a mod_http2 denial-of-service bug triggered by excessive size values in malicious HTTP/2 requests; CVE-2026-48913, a mod_http2 memory-corruption issue when file handles are exhausted; CVE-2026-34355 and CVE-2026-34356, buffer-overflow flaws tied to untrusted backend systems in mod_proxy_html and ProxyPassReverseCookie*; CVE-2026-44631, a heap underflow in ap_regname caused by crafted regular expressions; CVE-2026-29167, a mod_ldap per-directory use-after-free; CVE-2026-29170 and CVE-2026-44186 in mod_proxy_ftp; CVE-2026-44185 in mod_ssl OCSP handling; and CVE-2026-42535 in mod_dav_fs. The release also ships non-security changes such as OpenSSL 4.0 support and mod_http2 updates, but the immediate priority for exposed environments is upgrading all Apache HTTP Server deployments to 2.4.68.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
14 events from the most recent confirmed update back to the earliest known activity.
Apache released HTTP Server 2.4.68 on June 8, 2026 to fix 13 vulnerabilities affecting multiple modules, including mod_http2, mod_ssl, mod_proxy_ftp, mod_dav_fs, mod_ldap, mod_xml2enc, mod_headers, and mod_proxy_html. Apache advised users running earlier versions to upgrade to remediate the issues.
Debian published security advisory DSA-6323-1 for apache2. The reference indicates a product security update was issued, though no synopsis details are provided in the source content.
Apache committed fixes on June 5, 2026 for CVE-2026-34356, CVE-2026-42535, CVE-2026-43951, CVE-2026-44186, and CVE-2026-44631 in the 2.4.x branch. These changes addressed flaws in proxy cookie rewriting, WebDAV path handling, header merging, mod_proxy_ftp looping, and ap_regname heap underflow.
Apache committed fixes on June 4, 2026 for CVE-2026-34355, CVE-2026-29170, CVE-2026-42536, and CVE-2026-42536's related code revision r1934971. The changes addressed mod_proxy_html overflow, mod_proxy_ftp XSS, and mod_xml2enc heap overflow issues.
Apache fixed CVE-2026-48913 in revision r1934882 and CVE-2026-44185 in revision r1934919 in the 2.4.x branch. These addressed a mod_http2 memory-corruption issue and a mod_ssl stack buffer over-read.
Apache incorporated the previously upstreamed fix for CVE-2026-49975 into the 2.4.x branch. This prepared the HTTP/2 denial-of-service fix for inclusion in the next HTTP Server release.
The fix for CVE-2026-49975 was applied upstream in mod_h2. Apache later incorporated that change into the 2.4.x branch before the public release.
Apache received a report for CVE-2026-49975, a denial-of-service issue caused by excessive size values in the HTTP/2 component. The flaw affects Apache HTTP Server versions 2.4.17 through 2.4.67.
Apache received a report for CVE-2026-48913, a mod_http2 vulnerability that can lead to memory corruption when file handles are exhausted. Apache HTTP Server versions 2.4.55 through 2.4.67 are affected.
Apache received reports on April 27, 2026 for CVE-2026-42535, CVE-2026-42536, CVE-2026-43951, CVE-2026-44185, CVE-2026-44186, and CVE-2026-44631. These issues span mod_dav_fs, mod_xml2enc, mod_headers, mod_ssl, mod_proxy_ftp, and ap_regname, affecting versions through 2.4.67.
Apache received a report for CVE-2026-34355, a buffer overflow vulnerability in mod_proxy_html that can be triggered by an untrusted backend. The issue affects Apache HTTP Server versions 2.4.0 through 2.4.67.
Apache received a report for CVE-2026-29170, a cross-site scripting flaw in mod_proxy_ftp affecting HTML directory list generation for FTP directory contents. Apache HTTP Server 2.4.67 and earlier are affected.
Apache received a report for CVE-2026-29167, a use-after-free vulnerability in mod_ldap when used in per-directory configuration. Apache HTTP Server versions 2.4.0 through 2.4.67 are affected.
Apache received a report for CVE-2026-34356, a heap-based buffer overflow involving ProxyPassReverseCookie* when interacting with malicious backend servers. The flaw affects Apache HTTP Server versions 2.4.0 through 2.4.67.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
21 references tracked. Mallory keeps watching after this page renders.
cyber.gc.ca
Open sourcecybersecuritynews.com
Open sourcesecurityonline.info
Open sourcecvefeed.io
Open sourceseclists.org
Open sourceseclists.org
Open sourceseclists.org
Open sourcedownloads.apache.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.