The Apache Software Foundation released Apache HTTP Server 2.4.69 on October 1, 2026, addressing security flaws that could enable code execution, server crashes, data leaks, and authentication bypass under specific conditions. Apache identifies the update as the best available release of its web server.
The supplied advisory lists 20 vulnerabilities: five rated moderate and 15 rated low. Most affect versions 2.4.0 through 2.4.68, but exposure depends on enabled modules, server settings, and attacker access. The code execution risks have important limits and should not be treated as affecting every Apache installation.
CVE-2026-63292 affects mod_vhost_alias. A remote client could crash the server or potentially execute code through a Host header exceeding 8,192 bytes. Exploitation requires VirtualDocumentRoot to use a hostname format specifier and LimitRequestFieldSize to be raised above its default.
CVE-2026-42356 involves Apache selecting the wrong handler after certain internal redirects from CGI programs. The redirected file could be executed as CGI, but it must already exist in a CGI-enabled directory and lack an extension recognized by mod_mime. Versions 2.4.60 through 2.4.68 are affected.
These conditions matter: neither flaw establishes unrestricted code execution against default deployments. Earlier Apache HTTP Server code execution coverage examined a separate HTTP/2 double-free flaw fixed in version 2.4.67.
The following table summarizes the supplied advisory. Unless shown otherwise, affected versions are 2.4.0–2.4.68; all listed fixes are included in 2.4.69.
| CVE | Module or component | Severity | Vulnerability or impact |
|---|---|---|---|
| CVE-2026-42356 | CGI handling | Low | Limited code execution; 2.4.60–2.4.68. |
| CVE-2026-42528 | mod_dav | Moderate | Shared-lock overflow crashes child processes; through 2.4.68.* |
| CVE-2026-46729 | mod_heartmonitor | Low | Null pointer crash on unicast listener |
| CVE-2026-47360 | mod_session_cookie | Low | Session cookies reach backend after redirects. |
| CVE-2026-48005 | mod_auth_digest | Low | Forged headers force reauthentication |
| CVE-2026-56153 | mod_charset_lite | Low | Heap overflow in finish_partial_char |
| CVE-2026-56154 | mod_rewrite | Low | Use-after-free during lookahead |
| CVE-2026-56449 | mod_proxy_html | Low | Crafted response causes out-of-bounds write |
| CVE-2026-57941 | mod_http2 | Moderate | Shared-buffer use-after-free and memory write |
| CVE-2026-58415 | mod_dav_fs | Low | WebDAV property database disclosure |
| CVE-2026-59685 | Windows path handling | Moderate | Out-of-bounds write expanding short filenames. |
| CVE-2026-59797 | mod_ssl | Low | Privilege handling flaw in SSLRequire expressions. |
| CVE-2026-63045 | mod_proxy_ftp | Low | Crafted PASV reply redirects data connections. |
| CVE-2026-63292 | mod_vhost_alias | Moderate | Stack overflow; crashes or possible code execution. |
| CVE-2026-63686 | mod_xml2enc | Low | Failed charset conversion crashes proxy processing. |
| CVE-2026-63718 | mod_proxy_uwsgi | Low | Response smuggling; 2.4.30–2.4.68 |
| CVE-2026-73636 | mod_auth_digest | Low | Captured authentication credentials can be replayed |
| CVE-2026-73637 | mod_auth_digest | Low | Concurrent requests corrupt authentication state |
| CVE-2026-79768 | mod_userdir | Low | Information disclosure through path equivalence. |
| CVE-2026-93546 | mod_dav_fs | Moderate | Namespace overflow; crashes and database corruption; through 2.4.68. |
WebDAV users face availability and data risks. CVE-2026-93546 lets an authenticated client with write access crash workers and persistently corrupt a directory’s property database through PROPPATCH requests declaring many XML namespaces.
Proxy configurations also need attention. CVE-2026-63045 lets an untrusted FTP server direct a forward proxy’s data connection toward another host. CVE-2026-47360 can pass session cookies to a backend despite intended removal during internal redirects.
Administrators should upgrade to Apache HTTP Server 2.4.69, as the published CVE records recommend, and review whether the affected configurations are present.
Prioritize servers using the vulnerable virtual-host settings, CGI redirects, or WebDAV features. Check the Apache security advisory alongside individual CVE records for affected-version details and any later corrections. Apache notes that security impact can vary between platforms.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC
Travelers connecting to hotel Wi-Fi may now face more than an unreliable internet signal. A…
Meta and Microsoft are reducing employee use of Anthropic’s Claude AI while pushing their own…
ClingSTUN is a Linux backdoor that exploits vulnerable internet-connected devices to give attackers lasting remote…
The FBI removed an Accenture contractor on October 5, 2026, after a missed security patch…
Google has detailed six Advanced Protection enhancements for Android 17, targeting sophisticated attacks, scams and…
Atlassian has disclosed a critical arbitrary file access vulnerability affecting eight products, including Jira, Confluence,…