Apache HTTP Server Security Update – 09 June 2026

Apache has released a security update to address several vulnerabilities affecting Apache HTTP Server versions 2.4.67 and earlier, fixed in version 2.4.68.

The addressed vulnerabilities could allow the attacker to manipulate data, perform denial-of-service attacks and cross-site scripting attacks, obtain sensitive information, gain elevated privileges, or execute arbitrary code on the affected system.

Sample of the addressed vulnerabilities:

1. Apache HTTP Server Buffer Underwrite Vulnerability (CVE-2026-44631):

  • CVSS: 9.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Denial of Service

2. Apache HTTP Server Cross-Site Scripting exists in mod_proxy_ftp’s Vulnerability (CVE-2026-29170):

  • CVSS: 6.1
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Consequences: Cross-Site Scripting
Vulnerabilities
  • CVE-2026-29167
  • CVE-2026-29170
  • CVE-2026-34355
  • CVE-2026-34356
  • CVE-2026-42535
  • CVE-2026-42536
  • CVE-2026-43951
  • CVE-2026-44119
  • CVE-2026-44185
  • CVE-2026-44186
  • CVE-2026-44631
  • CVE-2026-48913
  • CVE-2026-49975
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Apache HTTP Server Security Advisory

References