# Multiple Vulnerabilities in Apache HTTP Server 2.4.0 through 2.4.68 (20 CVEs, fixed in 2.4.69)

> The Apache Software Foundation released HTTP Server 2.4.69 on 2026-10-01 fixing 20 CVEs across core and modules (mod_dav, mod_dav_fs, mod_auth_digest, mod_http2, mod_vhost_alias, mod_rewrite, mod_proxy_*). Apache rates 15 Low and 5 Moderate; none are noted as exploited in the wild. Hong Kong GovCERT alert A26-10-01 (2026-10-02) advises upgrading to 2.4.69 or later.

- **Published:** 2026-10-02T00:00:00Z
- **Last reviewed:** 2026-10-02T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2876
- **ID:** TL-2026-2876
- **Severity:** MEDIUM
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 10 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-42356, CVE-2026-42528, CVE-2026-46729, CVE-2026-47360, CVE-2026-48005, CVE-2026-56153, CVE-2026-56154, CVE-2026-56449, CVE-2026-57941, CVE-2026-58415, CVE-2026-59685, CVE-2026-59797, CVE-2026-63045, CVE-2026-63292, CVE-2026-63686, CVE-2026-63718, CVE-2026-73636, CVE-2026-73637, CVE-2026-79768, CVE-2026-93546

## Description

Apache HTTP Server 2.4.69, announced 2026-10-01, fixes 20 vulnerabilities affecting versions 2.4.0 through 2.4.68 (a few start later: CVE-2026-42356 from 2.4.60, CVE-2026-63718 from 2.4.30). The Apache security page publishes impact ratings only (low/moderate/important) and no CVSS scores; no entry is flagged as exploited in the wild, and no PoC, threat actor or network IOCs are cited by the sources.

Memory-safety issues: CVE-2026-63292 (mod_vhost_alias stack-based buffer overflow, Moderate) is triggered by an HTTP request whose Host header exceeds 8192 bytes when VirtualDocumentRoot uses a hostname format specifier and LimitRequestFieldSize has been raised above the default; it can cause denial of service or potentially arbitrary code execution. CVE-2026-57941 (mod_http2 use-after-free via shared session->bbtmp re-entrancy, Moderate), CVE-2026-59685 (out-of-bounds write in ap_directory_walk() on Windows case-blind filesystems with 8.3 names, Moderate), CVE-2026-42528 (mod_dav shared lock overflow, Moderate; crashes child processes for an attacker able to create WebDAV locks) and CVE-2026-93546 (mod_dav_fs integer overflow via PROPPATCH declaring many XML namespaces, Moderate; authenticated write access can crash workers and persistently corrupt a directory's property database) round out the Moderate set. Low-rated memory issues: CVE-2026-56153 (mod_charset_lite heap overflow in finish_partial_char), CVE-2026-56154 (mod_rewrite use-after-free with %{LA-U:HTTP:...} lookahead), CVE-2026-56449 (mod_proxy_html out-of-bounds write on crafted response bodies), CVE-2026-46729 (mod_heartmonitor NULL dereference on unicast listener), CVE-2026-63686 (mod_xml2enc NULL dereference on charset conversion failure).

Authentication and logic issues: three mod_auth_digest flaws share fix r1937721 - CVE-2026-48005 (forged Authorization headers force re-authentication DoS with AuthDigestNcCheck), CVE-2026-73636 (one-time-nonce capture-replay by a MITM when AuthDigestNonceLifetime is 0) and CVE-2026-73637 (use-after-free corrupting authentication state under concurrent requests). CVE-2026-42356 (Low) is a wrong-handler deployment: internal redirects from CGI programs to non-CGI files in CGI-enabled directories (2.4.60-2.4.68) may be treated as CGI and executed, giving limited RCE. CVE-2026-59797 (mod_ssl SSLRequire permits .htaccess ap_expr file functions) is an improper privilege management issue.

Information disclosure and proxy issues: CVE-2026-47360 (mod_session_cookie leaves the session cookie in place across internal redirects when SessionCookieRemove changes), CVE-2026-58415 (mod_dav_fs: GET of the .DAV state directory exposes WebDAV dead properties), CVE-2026-79768 (mod_userdir '/./' path equivalence with absolute non-wildcard UserDir), CVE-2026-63045 (mod_proxy_ftp trusts the PASV reply address, letting an untrusted FTP server make a forward proxy open data connections to arbitrary third-party hosts) and CVE-2026-63718 (mod_proxy_uwsgi Transfer-Encoding response smuggling).

Discovery credits include depthfirst, AISLE, Calif.io (in collaboration with Anthropic, for CVE-2026-93546), Altervista, Marlink Cyber and many independent researchers; reports date from 2026-04-03 to 2026-08-14. Severity is set to MEDIUM to match the vendor's ratings (no Important-rated issue in this release); the RCE-capable cases are conditional on non-default configuration. Fix: upgrade to 2.4.69 or later.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1059 Command and Scripting Interpreter
- T1557 Adversary-in-the-Middle
- T1499.004 Endpoint Denial of Service: Application or System Exploitation

## Sources

- [HKCERT/GovCERT Security Alert A26-10-01: Multiple Vulnerabilities in Apache HTTP Server](https://www.govcert.gov.hk/en/alerts_detail.php?id=2090)
- [Apache HTTP Server 2.4 vulnerabilities (fixed in 2.4.69)](https://httpd.apache.org/security/vulnerabilities_24.html#2.4.69)
- [Apache HTTP Server download (2.4.69 or later)](https://httpd.apache.org/download.cgi#apache24)
- [NVD: CVE-2026-63292 (mod_vhost_alias stack overflow)](https://nvd.nist.gov/vuln/detail/CVE-2026-63292)
- [CVE record: CVE-2026-93546 (mod_dav_fs namespace overflow)](https://www.cve.org/CVERecord?id=CVE-2026-93546)
- [CVE record: CVE-2026-42356 (CGI internal redirect handler)](https://www.cve.org/CVERecord?id=CVE-2026-42356)
- [CVE record: CVE-2026-57941 (mod_http2 use-after-free)](https://www.cve.org/CVERecord?id=CVE-2026-57941)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2876
