# Apache Software Foundation vulnerabilities & exploitation

**CISA KEV**

> As of 2026-10-05, Threadlinqs tracks 22 Apache Software Foundation CVEs, 1 in the CISA Known Exploited Vulnerabilities catalog, linked to 20 tracked threat campaigns and 2 named threat actors.

**Data as of:** 2026-10-05

## Exploitation timeline

Threadlinqs has recorded 22 Apache Software Foundation CVEs published between 2018-07-15 and 2026-09-15. The busiest month was 2026-08 (7 new CVEs). 1 of them (5%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.

## Most exploited vulnerabilities

Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 22 of 22 tracked Apache Software Foundation CVEs.

- [CVE-2026-34486](https://intel.threadlinqs.com/cve/CVE-2026-34486) — HIGH 7.5 · KEV · EPSS 42.6% · 2026-04-09
- [CVE-2021-39275](https://intel.threadlinqs.com/cve/CVE-2021-39275) — CRITICAL 9.8 · EPSS 39.4% · 2021-09-16
- [CVE-2018-8007](https://intel.threadlinqs.com/cve/CVE-2018-8007) — HIGH 7.2 · EPSS 11.7% · 2018-07-11
- [CVE-2026-43512](https://intel.threadlinqs.com/cve/CVE-2026-43512) — CRITICAL 9.8 · EPSS 1.2% · 2026-05-12
- [CVE-2026-23918](https://intel.threadlinqs.com/cve/CVE-2026-23918) — HIGH 8.8 · EPSS 1% · 2026-05-04
- [CVE-2026-40860](https://intel.threadlinqs.com/cve/CVE-2026-40860) — CRITICAL 9.8 · EPSS 0.9% · 2026-04-27
- [CVE-2026-40453](https://intel.threadlinqs.com/cve/CVE-2026-40453) — CRITICAL 9.9 · EPSS 0.9% · 2026-04-27
- [CVE-2026-30898](https://intel.threadlinqs.com/cve/CVE-2026-30898) — HIGH 8.8 · EPSS 0.8% · 2026-04-18
- [CVE-2026-33454](https://intel.threadlinqs.com/cve/CVE-2026-33454) — CRITICAL 9.4 · EPSS 0.6% · 2026-04-27
- [CVE-2026-68763](https://intel.threadlinqs.com/cve/CVE-2026-68763) — HIGH 7.5 · EPSS 0.5% · 2026-08-25
- [CVE-2026-68525](https://intel.threadlinqs.com/cve/CVE-2026-68525) — CRITICAL 9.1 · EPSS 0.5% · 2026-08-25
- [CVE-2026-65637](https://intel.threadlinqs.com/cve/CVE-2026-65637) — CRITICAL 9.8 · EPSS 0.5% · 2026-08-25
- [CVE-2026-65927](https://intel.threadlinqs.com/cve/CVE-2026-65927) — HIGH 7.5 · EPSS 0.5% · 2026-08-25
- [CVE-2026-65182](https://intel.threadlinqs.com/cve/CVE-2026-65182) — CRITICAL 9.1 · EPSS 0.5% · 2026-08-25
- [CVE-2026-68569](https://intel.threadlinqs.com/cve/CVE-2026-68569) — HIGH 8.1 · EPSS 0.4% · 2026-08-25
- [CVE-2026-66422](https://intel.threadlinqs.com/cve/CVE-2026-66422) — HIGH 8.1 · EPSS 0.4% · 2026-08-25
- [CVE-2026-97636](https://intel.threadlinqs.com/cve/CVE-2026-97636) — MEDIUM 6.5 · EPSS 0.4% · 2026-09-24
- [CVE-2026-55957](https://intel.threadlinqs.com/cve/CVE-2026-55957) — HIGH 7.3 · EPSS 0.2% · 2026-06-29
- [CVE-2026-50229](https://intel.threadlinqs.com/cve/CVE-2026-50229) — MEDIUM 6.1 · EPSS 0.2% · 2026-06-29
- [CVE-2026-55276](https://intel.threadlinqs.com/cve/CVE-2026-55276) — CRITICAL 9.1 · EPSS 0.2% · 2026-06-29
- [CVE-2026-55956](https://intel.threadlinqs.com/cve/CVE-2026-55956) — MEDIUM 6.5 · EPSS 0.2% · 2026-06-29
- [CVE-2026-55955](https://intel.threadlinqs.com/cve/CVE-2026-55955) — MEDIUM 6.5 · EPSS 0.1% · 2026-06-29

## Products affected

Threadlinqs normalises CPE and CNA product records across all 22 CVEs; 9 distinct Apache Software Foundation products are affected. The most frequently affected:

- Apache Tomcat — 14 CVEs
- Apache Camel — 2 CVEs
- Apache HTTP Server — 2 CVEs
- Apache Airflow — 1 CVE
- Apache Airflow HashiCorp provider — 1 CVE
- Apache Camel CoAP — 1 CVE
- Apache Camel Google PubSub — 1 CVE
- Apache Camel JMS — 1 CVE
- Apache CouchDB — 1 CVE

## Threat activity

20 tracked threat campaigns reference Apache Software Foundation products or exploit Apache Software Foundation CVEs:

- [Multiple Vulnerabilities in Apache HTTP Server 2.4.0 through 2.4.68 (20 CVEs, fixed in 2.4.69)](https://intel.threadlinqs.com/threat/TL-2026-2876) — MEDIUM — 2026-10-02
- [Endor Labs Discloses 14 Critical/High Vulnerabilities Across Seven AI Orchestration Platforms (NocoBase, Flowise, Langflow, Dify, Activepieces, Kestra, Apache Airflow)](https://intel.threadlinqs.com/threat/TL-2026-2438) — CRITICAL — 2026-09-10
- [Chinese-Speaking Operator "Nie" Uses SecFlow AI Orchestration Framework (Claude, Qwen, DeepSeek) and GLUTTON Steganographic Webshell in Multi-Country Espionage Campaign](https://intel.threadlinqs.com/threat/TL-2026-2325) — HIGH — 2026-09-04
- [Apache Tomcat 11.0.25 Fixes 11 Vulnerabilities Including HTTP/2 DoS, Authorization Bypass, and Auth Fail-Open Flaws — NVD Scores 5 of 11 CRITICAL/HIGH Despite Apache's Low/Moderate Ratings](https://intel.threadlinqs.com/threat/TL-2026-2159) — CRITICAL — 2026-08-26
- [AI-Assisted "HTTP Terminator" Uncovers Novel HTTP Desync Techniques and Apache Traffic Server Zero-Day (CVE-2026-63078)](https://intel.threadlinqs.com/threat/TL-2026-1961) — HIGH — 2026-08-09
- [CVE-2026-34486: Apache Tomcat EncryptInterceptor Bypass Actively Exploited in SnowLight and AI-Assisted Campaigns](https://intel.threadlinqs.com/threat/TL-2026-1885) — HIGH — 2026-08-05
- [Pre-auth RCE chains in Bonita BPM 10.4.3 and Apache OFBiz 24.09.05 (CVE-2026-31986)](https://intel.threadlinqs.com/threat/TL-2026-1898) — CRITICAL — 2026-08-05
- [Apache Syncope Patches 12 CVEs Including Groovy Sandbox Bypass RCE and Audit Search SQLi](https://intel.threadlinqs.com/threat/TL-2026-1666) — CRITICAL — 2026-07-24
- [Russian Intelligence Services Hijack Unsecured IP Cameras Across NATO, EU and Ukraine to Surveil Weapons Deliveries (AIVD/MIVD Advisory, Censys Analysis)](https://intel.threadlinqs.com/threat/TL-2026-1624) — HIGH — 2026-07-22
- [HollowByte: OpenSSL Pre-Authentication TLS DoS Flaw Bloats Server Memory With 11-Byte Payload](https://intel.threadlinqs.com/threat/TL-2026-1457) — MEDIUM — 2026-07-17
- [OpenSSL "HollowByte" TLS Handshake Memory-Amplification DoS (No CVE Assigned)](https://intel.threadlinqs.com/threat/TL-2026-1459) — MEDIUM — 2026-07-17
- [SAP July 2026 Patch Day: Critical Memory Corruption in NetWeaver ABAP (CVE-2026-44747, CVSS 9.9) Among 16 Security Notes](https://intel.threadlinqs.com/threat/TL-2026-1303) — CRITICAL — 2026-07-14
- [RustDuck Botnet Rebuilt in Rust with Enhanced C2 Capabilities and Multi-Vector Exploitation](https://intel.threadlinqs.com/threat/TL-2026-1006) — CRITICAL — 2026-06-30
- [Cordyceps: Systemic CI/CD Workflow Flaws Expose 300+ GitHub Repositories (Microsoft, Google, Apache, Cloudflare, PSF) to Supply-Chain Attacks](https://intel.threadlinqs.com/threat/TL-2026-1021) — CRITICAL — 2026-06-30
- [HTTP/2 Bomb — Remote DoS via HPACK Indexed-Reference Compression Bomb + Zero-Window Flow-Control Hold Affecting nginx, Apache httpd, IIS, Envoy & Cloudflare Pingora (CVE-2026-49975, Public PoC)](https://intel.threadlinqs.com/threat/TL-2026-0668) — HIGH — 2026-06-03
- [Apache ActiveMQ MessageServlet HTTP Response Header Injection (CVE-2026-42253) and Jolokia Default-Permission Privilege Issue (CVE-2026-49157)](https://intel.threadlinqs.com/threat/TL-2026-0675) — HIGH — 2026-06-03
- [BadHost CVE-2026-48710 — Starlette HTTP Host Header Authentication Bypass Affecting FastAPI/AI Infrastructure (MCP, vLLM, LiteLLM)](https://intel.threadlinqs.com/threat/TL-2026-0606) — CRITICAL — 2026-05-27
- [CVE-2026-23918 — Apache HTTP Server mod_http2 Double Free Enabling Unauthenticated DoS and Possible RCE](https://intel.threadlinqs.com/threat/TL-2026-0475) — CRITICAL — 2026-05-07
- [Apache ActiveMQ OpenWire Deserialization RCE (CVE-2023-46604) — 6,400 Brokers Actively Exploited by HelloKitty, Kinsing, TellYouThePass and Andariel (Lazarus)](https://intel.threadlinqs.com/threat/TL-2026-0404) — CRITICAL — 2026-04-21
- [Apache ActiveMQ Classic RCE via Jolokia JMX-HTTP Bridge (CVE-2026-34197)](https://intel.threadlinqs.com/threat/TL-2026-0337) — HIGH — 2026-04-08

## Threat actors targeting Apache Software Foundation

Named threat actors attributed to campaigns that involve Apache Software Foundation products or CVEs, with the number of linked campaigns:

- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 1 campaign
- [UNC5174](https://intel.threadlinqs.com/actor/UNC5174) — 1 campaign

## How to prioritise Apache Software Foundation patching

This order follows the data Threadlinqs holds for Apache Software Foundation, not a generic severity checklist:

- 1 of 22 Apache Software Foundation CVEs (5%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with [CVE-2026-34486](https://intel.threadlinqs.com/cve/CVE-2026-34486).
- Outside KEV, the highest EPSS scores are [CVE-2021-39275](https://intel.threadlinqs.com/cve/CVE-2021-39275) (39.4%), [CVE-2018-8007](https://intel.threadlinqs.com/cve/CVE-2018-8007) (11.7%), [CVE-2026-43512](https://intel.threadlinqs.com/cve/CVE-2026-43512) (1.2%).
- 9 CVEs score Critical and 9 High on CVSS v3 (maximum 9.9, average 8.3); sequence these after KEV and high-EPSS items.
- 7 CVEs have a public exploit or proof of concept recorded, which shortens the time from disclosure to attack.

## About this data

Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.

Canonical: https://intel.threadlinqs.com/vendors/apache-software-foundation
All vendors: https://intel.threadlinqs.com/vendors
Full detection coverage and IOCs via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
