Threat reportVulnerabilityTL-2026-2876
Multiple Vulnerabilities in Apache HTTP Server 2.4.0 through 2.4.68 (20 CVEs, fixed in 2.4.69)
Multiple Vulnerabilities in Apache HTTP Server 2.4.0 through (TL-2026-2876) is a medium-severity software vulnerability, first published 2026-10-02. It has no confirmed attribution, affects Apache Software Foundation Apache HTTP Server, references 20 CVEs (CVE-2026-42356, CVE-2026-42528, CVE-2026-46729), maps to 4 MITRE ATT&CK techniques (T1059, T1190, T1499.004), and is covered by 9 detection rules and 10 indicators of compromise.
- Severity
- MEDIUMAssessed severity
- CVEs
- 20Referenced vulnerabilities
- Techniques
- 4MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 10Indicators of compromise
Key facts for TL-2026-2876
- Threat ID
- TL-2026-2876
- Severity
- MEDIUM
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- government administration, technology, telecoms, finance, health
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 10
How Multiple Vulnerabilities in Apache HTTP Server 2.4.0 through works
The Apache Software Foundation released HTTP Server 2.4.69 on 2026-10-01 fixing 20 CVEs across core and modules (mod_dav, mod_dav_fs, mod_auth_digest, mod_http2, mod_vhost_alias, mod_rewrite, mod_proxy_*). Apache rates 15 Low and 5 Moderate; none are noted as exploited in the wild. Hong Kong GovCERT alert A26-10-01 (2026-10-02) advises upgrading to 2.4.69 or later.
Apache HTTP Server 2.4.69, announced 2026-10-01, fixes 20 vulnerabilities affecting versions 2.4.0 through 2.4.68 (a few start later: CVE-2026-42356 from 2.4.60, CVE-2026-63718 from 2.4.30). The Apache security page publishes impact ratings only (low/moderate/important) and no CVSS scores; no entry is flagged as exploited in the wild, and no PoC, threat actor or network IOCs are cited by the sources.
Memory-safety issues: CVE-2026-63292 (mod_vhost_alias stack-based buffer overflow, Moderate) is triggered by an HTTP request whose Host header exceeds 8192 bytes when VirtualDocumentRoot uses a hostname format specifier and LimitRequestFieldSize has been raised above the default; it can cause denial of service or potentially arbitrary code execution. CVE-2026-57941 (mod_http2 use-after-free via shared session->bbtmp re-entrancy, Moderate), CVE-2026-59685 (out-of-bounds write in ap_directory_walk() on Windows case-blind filesystems with 8.3 names, Moderate), CVE-2026-42528 (mod_dav shared lock overflow, Moderate; crashes child processes for an attacker able to create WebDAV locks) and CVE-2026-93546 (mod_dav_fs integer overflow via PROPPATCH declaring many XML namespaces, Moderate; authenticated write access can crash workers and persistently corrupt a directory's property database) round out the Moderate set. Low-rated memory issues: CVE-2026-56153 (mod_charset_lite heap overflow in finish_partial_char), CVE-2026-56154 (mod_rewrite use-after-free with %{LA-U:HTTP:...} lookahead), CVE-2026-56449 (mod_proxy_html out-of-bounds write on crafted response bodies), CVE-2026-46729 (mod_heartmonitor NULL dereference on unicast listener), CVE-2026-63686 (mod_xml2enc NULL dereference on charset conversion failure).
Authentication and logic issues: three mod_auth_digest flaws share fix r1937721 - CVE-2026-48005 (forged Authorization headers force re-authentication DoS with AuthDigestNcCheck), CVE-2026-73636 (one-time-nonce capture-replay by a MITM when AuthDigestNonceLifetime is 0) and CVE-2026-73637 (use-after-free corrupting authentication state under concurrent requests). CVE-2026-42356 (Low) is a wrong-handler deployment: internal redirects from CGI programs to non-CGI files in CGI-enabled directories (2.4.60-2.4.68) may be treated as CGI and executed, giving limited RCE. CVE-2026-59797 (mod_ssl SSLRequire permits .htaccess ap_expr file functions) is an improper privilege management issue.
Information disclosure and proxy issues: CVE-2026-47360 (mod_session_cookie leaves the session cookie in place across internal redirects when SessionCookieRemove changes), CVE-2026-58415 (mod_dav_fs: GET of the .DAV state directory exposes WebDAV dead properties), CVE-2026-79768 (mod_userdir '/./' path equivalence with absolute non-wildcard UserDir), CVE-2026-63045 (mod_proxy_ftp trusts the PASV reply address, letting an untrusted FTP server make a forward proxy open data connections to arbitrary third-party hosts) and CVE-2026-63718 (mod_proxy_uwsgi Transfer-Encoding response smuggling).
Discovery credits include depthfirst, AISLE, Calif.io (in collaboration with Anthropic, for CVE-2026-93546), Altervista, Marlink Cyber and many independent researchers; reports date from 2026-04-03 to 2026-08-14. Severity is set to MEDIUM to match the vendor's ratings (no Important-rated issue in this release); the RCE-capable cases are conditional on non-default configuration. Fix: upgrade to 2.4.69 or later.
MITRE ATT&CK techniques used in TL-2026-2876
Execution
T1059 Command and Scripting Interpreter
Initial Access
T1190 Exploit Public-Facing Application
Impact
T1499.004 Endpoint Denial of Service: Application or System Exploitation
Credential Access
Affected products and versions in Multiple Vulnerabilities in Apache HTTP Server 2.4.0 through
- Apache Software Foundation — Apache HTTP Server
Vulnerable versions: 2.4.0 through 2.4.68
Fixed in: 2.4.69
Remediation for Multiple Vulnerabilities in Apache HTTP Server 2.4.0 through
Patches
- Apache HTTP Server 2.4.69 (released 2026-10-01)
Immediate actions
- Upgrade Apache HTTP Server to 2.4.69 or later
- Inventory all hosts and containers running Apache httpd 2.4.0 through 2.4.68, including vendor-bundled builds
Workarounds
- Keep LimitRequestFieldSize at its default to limit CVE-2026-63292 exposure
- Restrict WebDAV (mod_dav/mod_dav_fs) to trusted authenticated users and deny access to .DAV directories
- Avoid AuthDigestNonceLifetime 0 and AuthDigestNcCheck configurations pending upgrade
- Do not enable forward proxying (mod_proxy_ftp) to untrusted FTP servers
Longer-term hardening
- Subscribe to the Apache httpd security announcements and track distro backports
- Disable modules that are not required (mod_dav, mod_dav_fs, mod_proxy_ftp, mod_heartmonitor, mod_userdir, mod_proxy_uwsgi)
CVEs associated with Multiple Vulnerabilities in Apache HTTP Server 2.4.0 through
CVE-2026-42356CVE-2026-42528CVE-2026-46729CVE-2026-47360CVE-2026-48005CVE-2026-56153CVE-2026-56154CVE-2026-56449CVE-2026-57941CVE-2026-58415CVE-2026-59685CVE-2026-59797CVE-2026-63045CVE-2026-63292CVE-2026-63686CVE-2026-63718CVE-2026-73636CVE-2026-73637CVE-2026-79768CVE-2026-93546
Timeline of Multiple Vulnerabilities in Apache HTTP Server 2.4.0 through
- Earliest report in the 2.4.69 batch: CVE-2026-42356 (CGI internal redirect handler) reported to the Apache HTTP Server security team by Feliks Penconek
- CVE-2026-42528 (mod_dav shared lock overflow) reported by depthfirst
- CVE-2026-93546 (mod_dav_fs namespace overflow) reported by Zhen Kong, Calif.io (with Anthropic) and AISLE (with Red Hat)
- Latest report in the batch: CVE-2026-79768 (mod_userdir information disclosure) reported by Marlink Cyber
- Apache HTTP Server 2.4.69 released; all 20 CVEs made public with fixes (r1937721 to r1938691)
- Hong Kong GovCERT/HKCERT publishes alert A26-10-01 advising upgrade to 2.4.69 or later
Sources cited for Multiple Vulnerabilities in Apache HTTP Server 2.4.0 through
- HKCERT/GovCERT Security Alert A26-10-01: Multiple Vulnerabilities in Apache HTTP Server
- Apache HTTP Server 2.4 vulnerabilities (fixed in 2.4.69)
- Apache HTTP Server download (2.4.69 or later)
- NVD: CVE-2026-63292 (mod_vhost_alias stack overflow)
- CVE record: CVE-2026-93546 (mod_dav_fs namespace overflow)
- CVE record: CVE-2026-42356 (CGI internal redirect handler)
- CVE record: CVE-2026-57941 (mod_http2 use-after-free)
Detection coverage for TL-2026-2876
As of 2026-10-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2876 across Splunk SPL, Microsoft KQL and Sigma, covering 10 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.