Apache released HTTP Server 2.4.69 to address 20 vulnerabilities in earlier 2.4.x releases, including potential remote code execution, memory corruption, response smuggling, information disclosure, and denial of service. Highlighted flaws affect CGI redirect handling (CVE-2026-42356), mod_http2 (CVE-2026-57941), mod_vhost_alias (CVE-2026-63292), and mod_proxy_uwsgi (CVE-2026-63718). Exploitability depends heavily on enabled modules and configuration; higher-risk deployments include mod_vhost_alias installations accepting Host headers longer than 8,192 bytes, WebDAV services granting authenticated write access, Windows-hosted servers, and certain proxy configurations. Severity assessments differ: Italy’s CSIRT classifies three vulnerabilities as critical and 13 as high, while another advisory highlights five Moderate-severity issues. Tenable rates the Alpine update Critical with a CVSS score of 9.8; its supplied plugin metadata reports no known exploits.
Organizations should prioritize upgrading to Apache HTTP Server 2.4.69 or distribution packages containing equivalent fixes. Tenable recommends 2.4.69-r0 or later for affected Alpine apache2 packages and separately flags CVE-2026-59797 as unpatched for Debian 12, 13, and 14; administrators should verify current vendor advisories and account for backported fixes rather than relying solely on upstream version numbers. Inventory installations, audit loaded modules and relevant directives, test updates, and confirm the running server uses the patched package. Where patching must be delayed, apply module-specific temporary controls to limit exposure, especially for publicly reachable services with the higher-risk configurations.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Tenable published Cloud Security plugin 472283 covering 20 CVEs in Alpine Linux apache2 packages and recommending version 2.4.69-r0 or later. The plugin is rated Critical with a CVSS v3 score of 9.8 and reports no known exploits.
The Apache Software Foundation released HTTP Server 2.4.69, addressing 20 vulnerabilities in earlier 2.4.x releases. Fixes cover configuration-dependent code execution, memory corruption, authentication and access-control weaknesses, information disclosure, and denial of service.
Tenable’s Apache HTTP Server vulnerability metadata records April 3, 2026, as a vulnerability publication date. The supplied excerpt does not identify which of the 20 referenced CVEs were published on that date.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
7 references tracked. Mallory keeps watching after this page renders.
boho.or.kr
Open sourcetenable.com
Open sourcelinuxsecurity.com
Open sourceacn.gov.it
Open sourcethecybersecguru.com
Open sourcetenable.com
Open sourcetenable.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.