Collected every two hours from specialised publications — each link leads to the original article.
MGASA-2025-0293 - Updated apache-commons-lang3 & apache-commons-lang packages fix security vulnerability
Apache Subversion could be made to crash if it opened a specially crafted file.
Apache Subversion could be made to crash if it opened a specially crafted file.
Several security issues were fixed in Apache HTTP Server.
Threat actors are exploiting a nearly two-year-old security flaw in Apache ActiveMQ to gain persistent access to cloud Linux systems and deploy malware called …
Multiple vulnerabilities have been addressed in Apache, a widely used web server. Please note that the fix for CVE-2025-23048, included in this DLA,
Let's talk straight: if you're running Apache HTTP Server and you haven't checked your version in a while, you might have a problem. An issue that's now pretty…
Apache HTTP Server 2.4.64 is here, and it's carrying quite a load of security fixes that Linux admins absolutely need to pay attention to. Whether your Apache …
Apache HTTP Server 2.4.64 is here, and it's carrying quite a load of security fixes that Linux admins absolutely need to pay attention to. Whether your Apache …
Apache Log4j could be made to run programs as your login if it opened a specially crafted file.
Several vulnerabilities were discovered in modsecurity-apache, an Apache module to tighten the Web application security, which may result in denial of service …
A vulnerability has been discovered in mod_auth_openidc, an OpenID Certified authentication and authorization module for the Apache HTTP server that implements…
A vulnerability has been fixed in mod_auth_openidc, an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements …
A critical security vulnerability has been disclosed in the Apache Roller open-source, Java-based blogging server software that could allow malicious actors to…
The Apache Software Foundation (ASF) has shipped security updates to address a critical security flaw in Traffic Control that, if successfully exploited, could…
The Apache Software Foundation (ASF) has released a security update to address an important vulnerability in its Tomcat server software that could result in re…
Multiple vulnerabilities have been found in Apache HTTPD, the worst of which could result in denial of service.
Incorrect Default Permissions vulnerability in Apache Tomcat Connectors allows local users to view and modify shared memory containing mod_jk configuration whi…
Hackers have recently been observed actively targeting the Apache AXIS server to deploy malicious web shells, exposing significant vulnerabilities and risks fo…
CVE-2024-40898: Apache HTTP Server: SSRF with mod_rewrite in server/vhost context on Windows (cve.mitre.org) SSRF in Apache HTTP Server on Windows with mod_rew…
Threat actors are actively exploiting a recently disclosed critical security flaw impacting Apache HugeGraph-Server that could lead to remote code execution at…
Multiple vulnerabilities have been discovered in the Apache HTTP server, which may result in authentication bypass, execution of scripts in directories not dir…
Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, degrading pe…
Despite a working patch that has been around for years, the Apache Log4j2 vulnerability still…Apache Log4j2 Vulnerability Remains A Threat For Global Finance o…