Apache Traffic Server has received security updates for 16 vulnerabilities, including four critical and eleven high-severity issues affecting versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. CSIRT Italia said the flaws can enable arbitrary code execution, denial of service, security restriction bypass, information disclosure, and tampering, and assigned the advisory a high systemic impact score. Apache recommends upgrading affected deployments to 9.2.15 or 10.1.4.
The published CVEs include CVE-2026-58150, a critical HTTP/2 Transfer-Encoding handling flaw that enables downgrade request smuggling, as well as CVE-2026-58159 for ACL bypass, CVE-2026-58161 for TLS/SNI memory-safety crashes, and CVE-2026-58151 for HTTP/2 resource-exhaustion denial of service. Additional issues affect multiple plugins, including ESI SSRF and recursion in CVE-2026-58178, stack and integer overflows in regex_remap (CVE-2026-58179), stack exhaustion in uri_signing and url_sig (CVE-2026-58181), resource-consumption flaws in ts_lua (CVE-2026-58182), crashes in prefetch (CVE-2026-58183), and memory-safety weaknesses in experimental plugins (CVE-2026-58188).

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
CSIRT Italia published an alert stating that security updates were available for multiple Apache Traffic Server vulnerabilities, including four critical and eleven high-severity issues. The notice highlighted impacts such as arbitrary code execution, denial of service, security restriction bypass, information disclosure, and tampering, and advised organizations to update according to the vendor bulletin.
On 2026-07-29, the Apache Software Foundation published a batch of vulnerability records for Apache Traffic Server affecting versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. The records recommend upgrading to versions 9.2.15 or 10.1.4 to remediate issues including request smuggling, access-control bypass, memory-safety flaws, denial of service, and plugin-specific bugs.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
16 references tracked. Mallory keeps watching after this page renders.
acn.gov.it
Open sourcecve.org
Open sourcecve.org
Open sourcecve.org
Open sourcecve.org
Open sourcecve.org
Open sourcecve.org
Open sourcecve.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.