Lyrie
← Home

#Apache

15 stories tagged.

Two Frames to Own the Server: CVE-2026-23918 and the Apache HTTP/2 Double-Free That Stole May's Patch Cycle

10 min · 0 sources

Two Frames, One Crash: CVE-2026-23918 and the Apache HTTP/2 Double-Free That Unlocks Unauthenticated RCE

9 min · 0 sources

The Data Lake Is Poisoned: Apache Polaris Triple CVSS-9.9 Cluster Exposes Enterprise Lakehouses to Credential Hijack and Arbitrary Storage Access

9 min · 0 sources

CRITICAL: CVE-2026-40010 (CVSS 9.1) — apache wicket

1 min · 3 sources

The Early Reset Kill Chain: CVE-2026-23918 Apache HTTP/2 Double-Free Enables Unauthenticated DoS and Working RCE PoC

10 min · 0 sources

The Web Server the World Forgot to Patch: CVE-2026-23918 and the Apache HTTP/2 Double-Free That Opens 60% of the Internet to RCE

8 min · 0 sources

The Incomplete Patch Trilogy: Apache MINA's Deserialization Crisis and the Allowlist That Wasn't (CVE-2026-42779, CVE-2026-42778, CVE-2026-41635)

10 min · 0 sources

CVE-2025-30065: Apache Parquet RCE — Perfect CVSS 10.0 Score

1 min · 0 sources

CISA: CVE-2026-34197 added to Known Exploited Vulnerabilities — Apache ActiveMQ

4 min · 3 sources

CISA: CVE-2024-38475 added to Known Exploited Vulnerabilities — Apache HTTP Server

4 min · 3 sources

CISA: CVE-2025-24813 added to Known Exploited Vulnerabilities — Apache Tomcat

1 min · 3 sources

CISA: CVE-2024-45195 added to Known Exploited Vulnerabilities — Apache OFBiz

1 min · 3 sources

CISA: CVE-2024-27348 added to Known Exploited Vulnerabilities — Apache HugeGraph-Server

1 min · 3 sources

CISA: CVE-2024-38856 added to Known Exploited Vulnerabilities — Apache OFBiz

1 min · 3 sources

CISA: CVE-2024-32113 added to Known Exploited Vulnerabilities — Apache OFBiz

1 min · 3 sources