Apache HTTP Server Security Update Advisory

Apache HTTP Server Security Update Advisory

Overview

A security update has been released to address vulnerabilities in the Apache HTTP Server. The affected versions vary by vulnerability; some are 2.4.0 Through 2.4.68, Some are 2.4.68, Some are 2.4.30 Through 2.4.68, And some are 2.4.68 Or earlier.

Resolved Vulnerabilities

  • CVE-2026-46729: NULL pointer dereference vulnerability.
  • CVE-2026-47360: Vulnerability exposing sensitive information to unauthorized users.
  • CVE-2026-48005: Denial-of-service (forced reauthentication) vulnerability.
  • CVE-2026-56153: Out-of-bounds write vulnerability.
  • CVE-2026-56154: Use-after-free vulnerability.
  • CVE-2026-56449: Out-of-bounds write vulnerability.
  • CVE-2026-57941: Use-after-free vulnerability.
  • CVE-2026-59685: Out-of-bounds write vulnerability.
  • CVE-2026-59797: Improper privilege management vulnerability.
  • CVE-2026-63045: Insufficient validation of FTP PASV response address vulnerability.
  • CVE-2026-63292: Stack buffer overflow vulnerability.
  • CVE-2026-63686: NULL pointer dereference vulnerability.
  • CVE-2026-63718: HTTP response smuggling vulnerability.
  • CVE-2026-73636: Authentication bypass vulnerability.
  • CVE-2026-73637: Use-after-free vulnerability.
  • CVE-2026-93546: Integer overflow vulnerability.

Recommended Actions

Vulnerability Patches have been provided via the latest update, which includes instructions to update to the latest version of the Vulnerability Patch, 2.4.69, As outlined on the reference site.