Critical, High-Severity Vulnerabilities Patched in Apache MINA, HTTP Server
Apache releases patches for critical RCE vulnerabilities in HTTP Server and MINA.
Run Apache?
Get an email when a reviewed story names Apache, usually within the hour.
Free. Your list stays private and never appears in a subject line. One click stops it. How Vendor Watch works
Summary
Apache has released patches for multiple vulnerabilities in HTTP Server and MINA. The most severe of these flaws could allow remote attackers to execute arbitrary code or cause denial-of-service conditions. Users are advised to upgrade to the latest versions to mitigate these risks.
Full text
Apache on Monday released patches for over a dozen vulnerabilities in HTTP Server and MINA, including critical and high-severity issues that could be exploited for remote code execution (RCE). Apache HTTP Server 2.4.67 was released with fixes for 11 vulnerabilities, 10 of which affect all previous releases. The first is CVE-2026-23918, a double-free and possible RCE bug in the HTTP/2 protocol handling. By triggering an early reset, an attacker could cause a denial-of-service (DoS) condition and potentially execute arbitrary code. Next in line is CVE-2026-28780, a heap buffer overflow issue that could allow remote attackers to send crafted AJP messages to cause a DoS condition and execute code. Three other security defects, CVE-2026-29168, CVE-2026-29169, and CVE-2026-33007, could lead to DoS conditions, while four, namely CVE-2026-24072, CVE-2026-33857, CVE-2026-34032, and CVE-2026-34059, could lead to information disclosure. The update also addresses an improper neutralization of CRLF sequences issue, tracked as CVE-2026-33523, which allows attackers to manipulate HTTP responses, and a timing side-channel weakness (CVE-2026-33006) that could lead to Digest authentication bypass.Advertisement. Scroll to continue reading. On Monday, Apache announced the rollout of MINA 2.2.7 and MINA 2.1.12 with fixes for two critical-severity vulnerabilities that should have been addressed in previous releases. The first, CVE-2026-42778, is described as an incomplete fix for CVE-2026-41409, which in turn is an incomplete fix for CVE-2024-52046, an insecure deserialization of data that could be exploited for RCE. The second is CVE-2026-42779, an incomplete fix for CVE-2026-41635, an improper check flaw leading to allowlist bypass and code execution. Following the upgrade to a patched release, Apache says, organizations need to “explicitly allow the classes the decoder will accept in the ObjectSerializationDecoder instance”. Related: SonicWall Urges Immediate Patching of Firewall Vulnerabilities Related: No Patch for New PhantomRPC Privilege Escalation Technique in Windows Related: Incomplete Windows Patch Opens Door to Zero-Click Attacks Related: Vulnerabilities Patched in CrowdStrike, Tenable Products Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Geordie Raises $30 Million for AI Security and Governance PlatformCarnival Data Breach Exposed 6 Million PeopleNew BTMOB Android Malware Enables Full Device TakeoverCritical FortiClient EMS Vulnerability Exploited in Fresh AttacksGitea Vulnerability Exposed 30,000 Deployments to AttacksGoogle Unveils AI Threat Defense Platform to Fight AI-Powered CyberattacksRevEng.AI Raises $15 Million to Hunt for Flaws and Backdoors in Software BinariesGlassWorm Botnet Disrupted Latest News Russian Spies Are Aggressively Seeking Western Technology as Sanctions Bite, Officials SayExploit Code Published for Critical Flowise RCE VulnerabilityIn Other News: Trump Mobile Data Breach, FIFA World Cup Phishing, CISA Responds to Supply Chain AttacksCharter Communications Data Breach Could Impact Nearly 5 MillionMokN Raises $15 Million for Phish-Back PlatformGogs Zero-Day Exposes Servers to Remote Code ExecutionCalifornia Sues 23andMe, Alleging It Failed to Protect User Data in 2023 BreachChrome 148 Update Patches 151 Vulnerabilities Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Threat Detection and Incident Response Summit On-Demand Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization. Register Webinar: Third-Party Risk in Practice June 4, 2026 Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice. Register People on the MoveAnurag Jain has been appointed Senior Vice President of Engineering at CodeHunterCTERA has appointed Tal Sarfaty as Senior Vice President of Cybersecurity.Quantum Secure Encryption has named Michael Massing as Chief Technology Officer.More People On The MoveExpert Insights Raising the Cybersecurity Stakes: Ante up for the Agentic Era CISOs are now facing machine-speed attacks and asking, “How do I agent?” The industry must provide remediation at scale. (Nadir Izrael) Caught Off Guard: Securing AI After It Hits Production As enterprises rush AI projects into production, security teams are increasingly being forced into reactive mode. (Joshua Goldfarb) Cyber Resilience is the New Business Continuity Plan The organizations best prepared to face disruption are those that align security, continuity and risk management around what the business cannot afford to lose. (Steve Durbin) Enhancing Data Center Security Without Sacrificing Performance For AI data centers, where the stakes are the highest and performance constraints are the tightest, security and performance are no longer a zero-sum game. (Nadir Izrael) Is the SOC Obsolete, and We Just Haven’t Admitted It Yet? Many AI-first enterprises have already embraced sovereign architectures for general AI initiatives; cybersecurity—and the SOC—should be next. (Danelle Au) Flipboard Reddit Whatsapp Whatsapp Email
Indicators of Compromise
- cve — CVE-2026-23918
- cve — CVE-2026-28780
- cve — CVE-2026-29168
- cve — CVE-2026-29169
- cve — CVE-2026-33007
- cve — CVE-2026-24072
- cve — CVE-2026-33857
- cve — CVE-2026-34032
- cve — CVE-2026-34059
- cve — CVE-2026-33523
- cve — CVE-2026-33006
- cve — CVE-2026-42778
- cve — CVE-2026-42779
- cve — CVE-2026-41409
- cve — CVE-2026-41635
- cve — CVE-2024-52046