← Home
#Apache
15 stories tagged.
Two Frames to Own the Server: CVE-2026-23918 and the Apache HTTP/2 Double-Free That Stole May's Patch Cycle
10 min · 0 sources
Two Frames, One Crash: CVE-2026-23918 and the Apache HTTP/2 Double-Free That Unlocks Unauthenticated RCE
9 min · 0 sources
The Data Lake Is Poisoned: Apache Polaris Triple CVSS-9.9 Cluster Exposes Enterprise Lakehouses to Credential Hijack and Arbitrary Storage Access
9 min · 0 sources
CRITICAL: CVE-2026-40010 (CVSS 9.1) — apache wicket
1 min · 3 sources
The Early Reset Kill Chain: CVE-2026-23918 Apache HTTP/2 Double-Free Enables Unauthenticated DoS and Working RCE PoC
10 min · 0 sources
The Web Server the World Forgot to Patch: CVE-2026-23918 and the Apache HTTP/2 Double-Free That Opens 60% of the Internet to RCE
8 min · 0 sources
The Incomplete Patch Trilogy: Apache MINA's Deserialization Crisis and the Allowlist That Wasn't (CVE-2026-42779, CVE-2026-42778, CVE-2026-41635)
10 min · 0 sources
CVE-2025-30065: Apache Parquet RCE — Perfect CVSS 10.0 Score
1 min · 0 sources
CISA: CVE-2026-34197 added to Known Exploited Vulnerabilities — Apache ActiveMQ
4 min · 3 sources
CISA: CVE-2024-38475 added to Known Exploited Vulnerabilities — Apache HTTP Server
4 min · 3 sources
CISA: CVE-2025-24813 added to Known Exploited Vulnerabilities — Apache Tomcat
1 min · 3 sources
CISA: CVE-2024-45195 added to Known Exploited Vulnerabilities — Apache OFBiz
1 min · 3 sources
CISA: CVE-2024-27348 added to Known Exploited Vulnerabilities — Apache HugeGraph-Server
1 min · 3 sources
CISA: CVE-2024-38856 added to Known Exploited Vulnerabilities — Apache OFBiz
1 min · 3 sources
CISA: CVE-2024-32113 added to Known Exploited Vulnerabilities — Apache OFBiz
1 min · 3 sources