The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
A vulnerability has been discovered in mod_auth_openidc, an OpenID Certified authentication and authorization module for the Apache HTTP server that implements…
A vulnerability has been fixed in mod_auth_openidc, an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements …
Apache Traffic Server could be made to crash if it received specially crafted network traffic.
A critical security vulnerability has been disclosed in the Apache Roller open-source, Java-based blogging server software that could allow malicious actors to…
Several security issues were fixed in Apache ActiveMQ.
Apache Commons BCEL could be made to crash or run programs if it received specially crafted network traffic.
The Apache Software Foundation (ASF) has shipped security updates to address a critical security flaw in Traffic Control that, if successfully exploited, could…
The Apache Software Foundation (ASF) has released a security update to address an important vulnerability in its Tomcat server software that could result in re…
Apache Shiro could be made to run programs or expose sensitive information over the network.
It was discovered that there was a configuration issue in libapache-mod-jk, an Apache web server module used to forward requests from Apache to Tomcat using th…
Elastic researchers recently identified an advanced Linux malware campaign targeting Apache2 web servers, underscoring the need for sysadmins and cybersecurity…
Multiple vulnerabilities have been found in Apache HTTPD, the worst of which could result in denial of service.
Incorrect Default Permissions vulnerability in Apache Tomcat Connectors allows local users to view and modify shared memory containing mod_jk configuration whi…
Hackers have recently been observed actively targeting the Apache AXIS server to deploy malicious web shells, exposing significant vulnerabilities and risks fo…
Several security issues were fixed in Apache HTTP Server.
Apache Commons Collections could be made to execute arbitrary code if it received specially crafted input.
Several security issues were fixed in Apache ActiveMQ.
CVE-2024-40898: Apache HTTP Server: SSRF with mod_rewrite in server/vhost context on Windows (cve.mitre.org) SSRF in Apache HTTP Server on Windows with mod_rew…
Apache HTTP Server could be made to expose sensitive information over the network.
Threat actors are actively exploiting a recently disclosed critical security flaw impacting Apache HugeGraph-Server that could lead to remote code execution at…
USN-6885-1 introduced a regression in Apache HTTP Server.
Multiple vulnerabilities have been discovered in the Apache HTTP server, which may result in authentication bypass, execution of scripts in directories not dir…
Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, degrading pe…
Several security issues were fixed in Apache HTTP Server.