The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
Apache's September 30, 2026 advisory, CVE-2026-88789, warns that an XML document can make an affected Camel Quarkus application read files or contact internal …
Gentoo Linux has issued a high-severity security advisory for Apache HTTPD, highlighting multiple vulnerabilities that could allow remote code execution, urgin…
Mageia released updates for security vulnerabilities in Apache HTTP Server affecting versions 10 and 9, addressing multiple issues including buffer overflows a…
Multiple vulnerabilities have been discovered in the Apache HTTP server, which may result in remote code execution, privilege escalation, denial of service or …
MGASA-2025-0296 - Updated apache-commons-fileupload packages fix security vulnerability
Several security issues were fixed in Apache ActiveMQ.
Apache Commons BCEL could be made to crash or run programs if it received specially crafted network traffic.
Apache Shiro could be made to run programs or expose sensitive information over the network.
It was discovered that there was a configuration issue in libapache-mod-jk, an Apache web server module used to forward requests from Apache to Tomcat using th…
Multiple vulnerabilities have been found in Apache HTTPD, the worst of which could result in denial of service.
Incorrect Default Permissions vulnerability in Apache Tomcat Connectors allows local users to view and modify shared memory containing mod_jk configuration whi…
Several security issues were fixed in Apache HTTP Server.
Apache Commons Collections could be made to execute arbitrary code if it received specially crafted input.
Several security issues were fixed in Apache ActiveMQ.
CVE-2024-40898: Apache HTTP Server: SSRF with mod_rewrite in server/vhost context on Windows (cve.mitre.org) SSRF in Apache HTTP Server on Windows with mod_rew…
Apache HTTP Server could be made to expose sensitive information over the network.
USN-6885-1 introduced a regression in Apache HTTP Server.
Multiple vulnerabilities have been discovered in the Apache HTTP server, which may result in authentication bypass, execution of scripts in directories not dir…
Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, degrading pe…
Several security issues were fixed in Apache HTTP Server.
Multiple vulnerabilities have been discovered in the Apache HTTP server, which may result in HTTP response splitting, denial of service, or authorization bypas…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a security flaw impacting Apache Flink, an open-source, unified stream-proce…
Several security issues were fixed in Apache HTTP Server.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added six security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evid…