Apache HTTP Server Security Update Advisory
Overview
A security update has been released to address vulnerabilities in the Apache HTTP Server. The affected versions vary by vulnerability; some are 2.4.0 Through 2.4.68, Some are 2.4.68, Some are 2.4.30 Through 2.4.68, And some are 2.4.68 Or earlier.
Resolved Vulnerabilities
CVE-2026-46729: NULL pointer dereference vulnerability.CVE-2026-47360: Vulnerability exposing sensitive information to unauthorized users.CVE-2026-48005: Denial-of-service (forced reauthentication) vulnerability.CVE-2026-56153: Out-of-bounds write vulnerability.CVE-2026-56154: Use-after-free vulnerability.CVE-2026-56449: Out-of-bounds write vulnerability.CVE-2026-57941: Use-after-free vulnerability.CVE-2026-59685: Out-of-bounds write vulnerability.CVE-2026-59797: Improper privilege management vulnerability.CVE-2026-63045: Insufficient validation of FTP PASV response address vulnerability.CVE-2026-63292: Stack buffer overflow vulnerability.CVE-2026-63686: NULL pointer dereference vulnerability.CVE-2026-63718: HTTP response smuggling vulnerability.CVE-2026-73636: Authentication bypass vulnerability.CVE-2026-73637: Use-after-free vulnerability.CVE-2026-93546: Integer overflow vulnerability.
Recommended Actions
Vulnerability Patches have been provided via the latest update, which includes instructions to update to the latest version of the Vulnerability Patch, 2.4.69, As outlined on the reference site.