Threat reportVulnerabilityTL-2026-2876

Multiple Vulnerabilities in Apache HTTP Server 2.4.0 through 2.4.68 (20 CVEs, fixed in 2.4.69)

mediumPATCHED

Multiple Vulnerabilities in Apache HTTP Server 2.4.0 through (TL-2026-2876) is a medium-severity software vulnerability, first published 2026-10-02. It has no confirmed attribution, affects Apache Software Foundation Apache HTTP Server, references 20 CVEs (CVE-2026-42356, CVE-2026-42528, CVE-2026-46729), maps to 4 MITRE ATT&CK techniques (T1059, T1190, T1499.004), and is covered by 9 detection rules and 10 indicators of compromise.

Severity
MEDIUMAssessed severity
CVEs
20Referenced vulnerabilities
Techniques
4MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
10Indicators of compromise

Key facts for TL-2026-2876

Threat ID
TL-2026-2876
Severity
MEDIUM
Status
PATCHED
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
government administration, technology, telecoms, finance, health
Target regions
Global
Detection rules
9
Indicators of compromise
10

How Multiple Vulnerabilities in Apache HTTP Server 2.4.0 through works

The Apache Software Foundation released HTTP Server 2.4.69 on 2026-10-01 fixing 20 CVEs across core and modules (mod_dav, mod_dav_fs, mod_auth_digest, mod_http2, mod_vhost_alias, mod_rewrite, mod_proxy_*). Apache rates 15 Low and 5 Moderate; none are noted as exploited in the wild. Hong Kong GovCERT alert A26-10-01 (2026-10-02) advises upgrading to 2.4.69 or later.

Apache HTTP Server 2.4.69, announced 2026-10-01, fixes 20 vulnerabilities affecting versions 2.4.0 through 2.4.68 (a few start later: CVE-2026-42356 from 2.4.60, CVE-2026-63718 from 2.4.30). The Apache security page publishes impact ratings only (low/moderate/important) and no CVSS scores; no entry is flagged as exploited in the wild, and no PoC, threat actor or network IOCs are cited by the sources.

Memory-safety issues: CVE-2026-63292 (mod_vhost_alias stack-based buffer overflow, Moderate) is triggered by an HTTP request whose Host header exceeds 8192 bytes when VirtualDocumentRoot uses a hostname format specifier and LimitRequestFieldSize has been raised above the default; it can cause denial of service or potentially arbitrary code execution. CVE-2026-57941 (mod_http2 use-after-free via shared session->bbtmp re-entrancy, Moderate), CVE-2026-59685 (out-of-bounds write in ap_directory_walk() on Windows case-blind filesystems with 8.3 names, Moderate), CVE-2026-42528 (mod_dav shared lock overflow, Moderate; crashes child processes for an attacker able to create WebDAV locks) and CVE-2026-93546 (mod_dav_fs integer overflow via PROPPATCH declaring many XML namespaces, Moderate; authenticated write access can crash workers and persistently corrupt a directory's property database) round out the Moderate set. Low-rated memory issues: CVE-2026-56153 (mod_charset_lite heap overflow in finish_partial_char), CVE-2026-56154 (mod_rewrite use-after-free with %{LA-U:HTTP:...} lookahead), CVE-2026-56449 (mod_proxy_html out-of-bounds write on crafted response bodies), CVE-2026-46729 (mod_heartmonitor NULL dereference on unicast listener), CVE-2026-63686 (mod_xml2enc NULL dereference on charset conversion failure).

Authentication and logic issues: three mod_auth_digest flaws share fix r1937721 - CVE-2026-48005 (forged Authorization headers force re-authentication DoS with AuthDigestNcCheck), CVE-2026-73636 (one-time-nonce capture-replay by a MITM when AuthDigestNonceLifetime is 0) and CVE-2026-73637 (use-after-free corrupting authentication state under concurrent requests). CVE-2026-42356 (Low) is a wrong-handler deployment: internal redirects from CGI programs to non-CGI files in CGI-enabled directories (2.4.60-2.4.68) may be treated as CGI and executed, giving limited RCE. CVE-2026-59797 (mod_ssl SSLRequire permits .htaccess ap_expr file functions) is an improper privilege management issue.

Information disclosure and proxy issues: CVE-2026-47360 (mod_session_cookie leaves the session cookie in place across internal redirects when SessionCookieRemove changes), CVE-2026-58415 (mod_dav_fs: GET of the .DAV state directory exposes WebDAV dead properties), CVE-2026-79768 (mod_userdir '/./' path equivalence with absolute non-wildcard UserDir), CVE-2026-63045 (mod_proxy_ftp trusts the PASV reply address, letting an untrusted FTP server make a forward proxy open data connections to arbitrary third-party hosts) and CVE-2026-63718 (mod_proxy_uwsgi Transfer-Encoding response smuggling).

Discovery credits include depthfirst, AISLE, Calif.io (in collaboration with Anthropic, for CVE-2026-93546), Altervista, Marlink Cyber and many independent researchers; reports date from 2026-04-03 to 2026-08-14. Severity is set to MEDIUM to match the vendor's ratings (no Important-rated issue in this release); the RCE-capable cases are conditional on non-default configuration. Fix: upgrade to 2.4.69 or later.

MITRE ATT&CK techniques used in TL-2026-2876

Execution

T1059 Command and Scripting Interpreter

Initial Access

T1190 Exploit Public-Facing Application

Impact

T1499.004 Endpoint Denial of Service: Application or System Exploitation

Credential Access

T1557 Adversary-in-the-Middle

Affected products and versions in Multiple Vulnerabilities in Apache HTTP Server 2.4.0 through

Remediation for Multiple Vulnerabilities in Apache HTTP Server 2.4.0 through

Patches

  • Apache HTTP Server 2.4.69 (released 2026-10-01)

Immediate actions

  • Upgrade Apache HTTP Server to 2.4.69 or later
  • Inventory all hosts and containers running Apache httpd 2.4.0 through 2.4.68, including vendor-bundled builds

Workarounds

  • Keep LimitRequestFieldSize at its default to limit CVE-2026-63292 exposure
  • Restrict WebDAV (mod_dav/mod_dav_fs) to trusted authenticated users and deny access to .DAV directories
  • Avoid AuthDigestNonceLifetime 0 and AuthDigestNcCheck configurations pending upgrade
  • Do not enable forward proxying (mod_proxy_ftp) to untrusted FTP servers

Longer-term hardening

  • Subscribe to the Apache httpd security announcements and track distro backports
  • Disable modules that are not required (mod_dav, mod_dav_fs, mod_proxy_ftp, mod_heartmonitor, mod_userdir, mod_proxy_uwsgi)

CVEs associated with Multiple Vulnerabilities in Apache HTTP Server 2.4.0 through

  • CVE-2026-42356
  • CVE-2026-42528
  • CVE-2026-46729
  • CVE-2026-47360
  • CVE-2026-48005
  • CVE-2026-56153
  • CVE-2026-56154
  • CVE-2026-56449
  • CVE-2026-57941
  • CVE-2026-58415
  • CVE-2026-59685
  • CVE-2026-59797
  • CVE-2026-63045
  • CVE-2026-63292
  • CVE-2026-63686
  • CVE-2026-63718
  • CVE-2026-73636
  • CVE-2026-73637
  • CVE-2026-79768
  • CVE-2026-93546

Timeline of Multiple Vulnerabilities in Apache HTTP Server 2.4.0 through

  • Earliest report in the 2.4.69 batch: CVE-2026-42356 (CGI internal redirect handler) reported to the Apache HTTP Server security team by Feliks Penconek
  • CVE-2026-42528 (mod_dav shared lock overflow) reported by depthfirst
  • CVE-2026-93546 (mod_dav_fs namespace overflow) reported by Zhen Kong, Calif.io (with Anthropic) and AISLE (with Red Hat)
  • Latest report in the batch: CVE-2026-79768 (mod_userdir information disclosure) reported by Marlink Cyber
  • Apache HTTP Server 2.4.69 released; all 20 CVEs made public with fixes (r1937721 to r1938691)
  • Hong Kong GovCERT/HKCERT publishes alert A26-10-01 advising upgrade to 2.4.69 or later

Sources cited for Multiple Vulnerabilities in Apache HTTP Server 2.4.0 through

Detection coverage for TL-2026-2876

As of 2026-10-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2876 across Splunk SPL, Microsoft KQL and Sigma, covering 10 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
10 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats