Apache HTTP Server 2.4.69 arrived on October 1 with fixes for 20 vulnerabilities. None are rated important or critical in the Apache advisory. Five are moderate, fifteen are low.
Know what this scale means before you decide how urgently to patch. Apache’s severity rating reflects its own assessment of realistic exploitation, and other databases have scored some of these considerably higher.
What is fixed
The versions affected vary by theme, so “2.4.0 to 2.4.68” is true for most but not all.
| CVE | Module | emission | Assessment |
|---|---|---|---|
| 2026-63292 | mod_vhost_alias | Floor overflow, possible RCE | mediocre |
| 2026-93546 | mod_dav_fs | Integer overflow, property DB corruption | mediocre |
| 2026-57941 | mod_http2 | Use-no-free via shared bbtmp | mediocre |
| 2026-59685 | Core (Windows) | Out-of-bounds writes in 8.3 ways | mediocre |
| 2026-42528 | mod_dav | Common lock flood, child crash | mediocre |
| 2026-42356 | CGI handling | Limit RCE to internal redirects | low |
| 2026-56154 | mod_rewrite | Use-after-free via %{LA-U:HTTP:...} | low |
| 2026-59797 | mod_ssl | Privilege management via SSLRequire | low |
| 2026-63045 | mod_proxy_ftp | PASV address validation | low |
| 2026-63718 | mod_proxy_uwsgi | Answer smuggling | low |
| 2026-79768 | is mod_user | Path Equivalence Disclosure | low |
| 2026-58415 | mod_dav_fs | Property database read access | low |
Plus eight more covers mod_heartmonitor, mod_session, mod_charset_lite, mod_proxy_html, mod_xml2enc and three separate mod_auth_digest issues.
Three flaws Apache calls low are 9.8 critical scored elsewhere
Three of these carry a criticality rating of 9.8 in the National Vulnerability Database, while Apache rates all three low:
| CVE | Module | weakness | Apache | NVD page |
|---|---|---|---|---|
| 2026-56154 | mod_rewrite | CWE-416 Use After Free | low | 9.8 critical |
| 2026-57941 | mod_http2 | CWE-416 Use After Free | low | 9.8 critical |
| 2026-59797 | mod_ssl | CWE-269 Incorrect privilege management | low | 9.8 critical |
Attribution is important here, as it is loosely reported. NIST didn’t score any of them. All three NVD entries read “NVD rating not yet provided” in the NIST base score field. The 9.8 comes out CISA Authorized Data Publisher Programthe entries enriched NVD has not yet processed.
So the exact statement is that CISA scored them 9.8, NVD didn’t score them at all, and Apache scored them low.
One more detail can be seen on all three sides. Each has the identical vector string: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Network reachable, low complexity, no privileges, no user interaction, high impact on confidentiality, integrity and availability.
The first to watch
- mod_vhost_alias stack overflow. A remote client can cause denial of service or potentially execute code via a host header exceeding 8192 bytes. It needs VirtualDocumentRoot with a hostname format specifier and LimitRequestFieldSize increased above the default, so check if that describes your configuration.
- CGI internal redirects. The target of some internal redirects from CGI programs can itself be treated as CGI and executed. It must already be sitting in a CGI-enabled directory without an extension mod_mime recognizes. Affects only 2.4.60 to 2.4.68.
- mod_dav_fs integer overflow. An authenticated WebDAV client with write access can crash worker processes and persistently corrupt a directory’s properties database through PROPPATCH requests that declare many XML namespaces.
- mod_auth_digest. Three separate issues in one release: forced reauthentication of unauthenticated clients, a capture-replay authentication bypass, and a use-free caused authentication state corruption. If you’re still using digest authentication, this is a question to think about.
Who they found
The acknowledgments say something about how server security research is done now.
CVE-2026-93546 credits Zhen Kong, Calif.io in collaboration with Anthropic, and AISLE in collaboration with Red Hat. The earlier release, 2.4.68, credits Quang Luong of Calif.IO in collaboration with the OpenAI Codex. Other finders include striga.ai, innora.ai, and depthfirst.
Several individual researchers appear again and again. Zhen Kong is credited on six of these twenty. Lucian Nitescu is credited on three.
Twenty CVEs in a single release of software this mature is unusual, and the pattern matches what OpenSSH described in its own release notes last week: more reports are coming, many are AI-assisted, and projects are shipping more often to keep.
Upgrade
Version 2.4.69 is the fix for all 20. There are no partial mitigations published for most of them.
If you’re running Apache behind a package manager, check if your distribution has backported the fixes instead of shipping 2.4.69 directly, as Debian, Ubuntu, RHEL, and others typically patch in place and keep the old version number.
