The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
Apache released Thrift 0.25.0 on Sep 30, 2026 with memory checks for several C++, Java, and Python components.
Apache’s release notice on Oct 3, 2026 lists six Apache Directory LDAP API vulnerabilities.
Apache released HTTP Server 2.4.69 on October 1, 2026, to fix security faults ranging from unwanted code execution to mishandled web responses.
Apache detailed two Apache APISIX vulnerabilities in notices issued on October 1, 2026.
Apache disclosed CVE-2026-94250 on October 1, 2026, warning that public access to a batch-request endpoint can let an attacker exhaust a gateway worker's memor…
Apache's September 30, 2026 advisory, CVE-2026-88789, warns that an XML document can make an affected Camel Quarkus application read files or contact internal …
It was discovered that incorrect state cookie parsing in mod_auth_openidc, an OpenID Certified authentication and authorisation module for the Apache HTTP serv…
USN-8571-1 introduced a regression in Apache HTTP Server.
Gentoo Linux has issued a high-severity security advisory for Apache HTTPD, highlighting multiple vulnerabilities that could allow remote code execution, urgin…
SUSE released a security update addressing CVE-2026-26032, which allows arbitrary file writes, alongside updates for apache-commons-compress and apache-ivy, ap…
An update for openSUSE Tumbleweed addresses four security vulnerabilities in the apache-sshd-2.19.0-2.1 package, enhancing system protection against identified…
Mageia released updates for security vulnerabilities in Apache HTTP Server affecting versions 10 and 9, addressing multiple issues including buffer overflows a…
A regression was introduced in Apache Commons BeanUtils affecting Ubuntu 16.04 LTS due to an incomplete fix for CVE-2014-0114 and CVE-2019-10086, which could a…
Ubuntu issued a security notice regarding a regression in libapache-mod-jk affecting version 16.04 LTS, reintroducing a fix for CVE-2023-41081 due to a previou…
Several security issues were fixed in Apache HTTP Server.
Several security issues were fixed in Apache HTTP Server.
Apache MINA could be made to run programs if it received specially crafted network traffic.
Cybersecurity researchers have discovered a remote denial-of-service exploit that affects major web servers, including NGINX, Apache HTTPD, Microsoft IIS, Envo…
Multiple vulnerabilities have been discovered in the Apache HTTP server, which may result in remote code execution, privilege escalation, denial of service or …
MGASA-2026-0129 - Updated apache packages fix security vulnerabilities
Multiple vulnerabilities have been discovered in the Apache HTTP server, which may result in remote code execution, privilege escalation, denial of service or …
Multiple vulnerabilities have been discovered in the Apache HTTP server, which may result in remote code execution, privilege escalation, denial of service or …
USN-7968-1 introduced a regression in Apache HTTP Server
In Apache Log4j2, a Java Logging Framework, the Socket Appender does not perform TLS hostname verification of the peer certificate, even when the verifyHostNam…