A server rack undergoes a software update, surrounded by glowing cybersecurity shield icons in a data center.
Apache HTTP Server 2.4.69 fixes 20 security bugs, and Apache's own security team didn't rate any of them "important" or "critical." That doesn't mean you can skip the update. Apache's severity labels are its own judgment of how likely real-world exploitation is. Other organisations scored some of the same bugs much higher, and one of them only affects Windows builds of httpd.

The release in brief​

On October 1, the Apache Software Foundation released Apache HTTP Server 2.4.69 with fixes for 20 security flaws. Five rate moderate, led by a mod_vhost_alias stack overflow that may allow code execution. The rest rate low, and no attacks have been reported.

Apache's release announcement calls 2.4.69 the latest general-availability release in the 2.4.x branch and recommends it over all earlier releases. It describes the update as a feature and bug-fix release. Some build details matter if you compile it yourself:

  • It needs APR and APR-Util 1.5.x or later.
  • Some features need version 1.6.x of both libraries.
  • Apache says the APR libraries must be upgraded for all httpd features to work correctly.

The announcement also repeats that the 2.2.x branch is past end of life and gets no more security patches. If you still have a 2.2 server somewhere, these 20 fixes won't reach it.

Section summary: Upstream Apache fixes 20 CVEs in 2.4.69. Apache rates five moderate and fifteen low, and none have been reported as exploited.

The five moderate-rated flaws​

These are the bugs Apache itself considers the most serious:

CVEComponentIssueAffected versions
CVE-2026-63292mod_vhost_aliasStack-based buffer overflow; DoS or possible code executionThrough 2.4.68
CVE-2026-93546mod_dav_fsInteger overflow; worker crashes and persistent property-database corruptionThrough 2.4.68
CVE-2026-57941mod_http2Use-after-free / wild write via shared session->bbtmp re-entrancy2.4.0–2.4.68
CVE-2026-59685Core (Windows only)Out-of-bounds write on 8.3 short-name paths that grow when expanded2.4.0–2.4.68
CVE-2026-42528mod_davMemory calculation bug; WebDAV lock creators can crash child processesThrough 2.4.68

Each one only bites under certain conditions:

  • mod_vhost_alias (CVE-2026-63292): Apache says a remote client can trigger the flaw using an oversized Host header when a server uses VirtualDocumentRoot with a hostname format specifier and has raised LimitRequestFieldSize above its default value. Apache's advisory puts the threshold at a Host header longer than 8,192 bytes. If you never raised that limit, you're likely not exposed. Some admins do raise it to fit large cookies or tokens, though.
  • mod_dav_fs (CVE-2026-93546): An attacker needs to be an authenticated WebDAV user with write access. They can send PROPPATCH requests that declare many XML namespaces, which crashes workers and can permanently corrupt a directory's property database. "Persistent corruption" is a worse outcome than a crash that ends when the process restarts.
  • mod_http2 (CVE-2026-57941): Memory-safety bugs in HTTP/2 processing are particularly relevant on internet-facing systems because requests are handled before application-level processing begins.
  • Windows core (CVE-2026-59685): This one affects Windows only. The bug is in how httpd handles paths using legacy 8.3 short names (the PROGRA~1 style) that get longer when expanded.
  • mod_dav locks (CVE-2026-42528): The finder is Zhenpeng (Leo) Lin at depthfirst, and the report was received 2026-04-27.

Section summary: All five moderate bugs depend on specific modules or settings. Check whether you use WebDAV, HTTP/2, hostname-based virtual document roots, or a Windows host.

The fifteen low-rated flaws​

"Low" here doesn't mean harmless. Several of these are worth a look depending on your setup:

  • CVE-2026-42356 (CGI handling): A CGI program's internal redirect could cause Apache to run the destination file as another program. Still, the target file must already sit in a CGI-enabled folder. It also needs a file with no other extension that mod_mime recognises, and it only affects 2.4.60 through 2.4.68.
  • CVE-2026-56154 (mod_rewrite): A use-after-free when rewrite rules use lookahead expressions like %{LA-U:HTTP:...}.
  • CVE-2026-59797 (mod_ssl): Improper privilege management involving SSLRequire and file-related expressions.
  • CVE-2026-63045 (mod_proxy_ftp): In forward-proxy setups, an untrusted FTP server can send a crafted PASV reply that makes the proxy open a data connection to an arbitrary third-party host.
  • CVE-2026-63718 (mod_proxy_uwsgi): Response smuggling through a crafted uWSGI response using Transfer-Encoding. It affects 2.4.30 through 2.4.68.
  • CVE-2026-79768 (mod_userdir): A /./ path-equivalence issue when UserDir uses the absolute, non-wildcard form.
  • CVE-2026-58415 (mod_dav_fs): A remote client can read WebDAV dead properties for resources it can't author by requesting the .DAV state directory.
  • CVE-2026-46729 (mod_heartmonitor): Denial of service through the unicast listener.
  • CVE-2026-47360 (mod_session_cookie): The session cookie can reach a backend after internal redirects.
  • CVE-2026-56153 (mod_charset_lite): An out-of-bounds write.
  • CVE-2026-56449 (mod_proxy_html): An out-of-bounds write triggered by crafted response bodies. It affects 2.4.68 only.
  • CVE-2026-63686 (mod_xml2enc): A NULL pointer dereference that lets an untrusted backend crash the server when a charset conversion partly succeeds and then fails.

Three of the low-rated bugs are in mod_auth_digest:

  • CVE-2026-48005: An unauthenticated remote client can cause a denial of service (forced re-authentication) via forged Authorization headers when Digest authentication is enabled with AuthDigestNcCheck.
  • CVE-2026-73636: A man-in-the-middle attacker can replay captured Digest authentication credentials in configurations where AuthDigestNonceLifetime is set to zero.
  • CVE-2026-73637: A use-after-free that lets concurrent requests corrupt authentication state when AuthDigestNcCheck is on or AuthDigestNonceLifetime is 0.

If you still use Digest authentication, three bugs in one release is a good reason to plan a move to TLS with something stronger. That's general advice, not something Apache says in this advisory.

Section summary: The low-rated list covers proxying, rewrites, WebDAV disclosure, and Digest auth. Whether any of it matters to you depends almost entirely on which modules you load.

The severity dispute​

How2Shout found that three of these CVEs carry a CVSS 3.1 score of 9.8 ("critical") on their National Vulnerability Database pages. The publication was right to be careful about who gave that score. NIST hadn't scored any of them, and the NVD base-score field read "NVD assessment not yet provided." The 9.8 came from CISA's Authorized Data Publisher (ADP) enrichment programme. All three pages showed the same vector, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. That vector describes a bug reachable over the network, with low complexity, needing no privileges or user interaction, and with high impact on confidentiality, integrity and availability.

One correction to How2Shout's version. Its comparison table says Apache rated all three bugs low, but Apache's advisory lists the mod_http2 bug, CVE-2026-57941, as moderate. Apache did rate the mod_rewrite (CVE-2026-56154) and mod_ssl (CVE-2026-59797) bugs low. An independent check of the NVD page confirmed the CISA-ADP 9.8 for CVE-2026-57941 and CVE-2026-59797. The 9.8 for CVE-2026-56154 rests on How2Shout's report.

CISA isn't the only outside body that disagrees with Apache. According to Mallory's aggregation, Italy's CSIRT classifies three vulnerabilities as critical and 13 as high, while another advisory highlights five Moderate-severity issues.

Who's right? Probably both, for different reasons:

  • CVSS enrichment often scores the worst-case shape of a bug class. A use-after-free reachable over the network gets the full 9.8 even when real exploitation needs uncommon settings.
  • Apache's ratings take those settings into account. A bug that needs LimitRequestFieldSize raised, or a niche lookahead rewrite rule, gets marked down. Apache's advisory page also says its ratings may vary from platform to platform.

In practice, use Apache's labels to understand how likely exploitation is. Remember that many vulnerability scanners and compliance dashboards will show the 9.8, so auditors will probably ask you about these CVEs either way.

Section summary: Credit the 9.8 to CISA-ADP, not NIST. Apache rated the mod_http2 bug moderate, not low, and your scanners will probably flag these as critical.

Who found the bugs​

The credits point to a trend. CVE-2026-93546 is credited to Zhen Kong, to Calif.io working with Anthropic, and to AISLE working with Red Hat. How2Shout notes that the previous release, 2.4.68, credited Quang Luong of Calif.IO working with OpenAI Codex. Other credited finders include striga.ai, innora.ai and depthfirst. Zhen Kong appears on six of the twenty CVEs and Lucian Nitescu on three. How2Shout ties this to recent comments from the OpenSSH project: more bug reports are arriving, many of them AI-assisted, and projects are shipping releases more often to keep up.

For admins, the takeaway is simple. AI-assisted bug hunting means more CVEs in mature software like httpd, so expect more frequent patch releases.

What to do on Windows and Linux​

  1. Check your version. On Linux, run httpd -v, apache2 -v or apachectl -v, depending on your distribution. On Windows, run httpd.exe -v from the Apache bin folder.
  2. List loaded modules. Run httpd -M (or apache2ctl -M). Look for mod_dav/mod_dav_fs, mod_http2, mod_vhost_alias, mod_auth_digest, mod_proxy_ftp, mod_proxy_uwsgi, mod_userdir, mod_proxy_html, mod_xml2enc, mod_charset_lite and mod_heartmonitor. Unloading modules you don't use cuts your exposure right away.
  3. Review the risky settings. Check whether you use VirtualDocumentRoot with a raised LimitRequestFieldSize, AuthDigestNonceLifetime 0 or AuthDigestNcCheck, CGI-enabled directories that receive internal redirects, and WebDAV write grants.
  4. Upgrade. Upstream 2.4.69 fixes all 20 bugs, and How2Shout reports that most have no published partial workaround.
  5. Trust your distribution's advisory over the version number. Debian, Ubuntu, RHEL and others often backport fixes and keep the old version string. Tenable recommends 2.4.69-r0 or later for affected Alpine apache2 packages and separately flags CVE-2026-59797 as unpatched for Debian 12, 13, and 14, according to Mallory's summary. Check the current status for your own release.

Windows hosts need extra attention because of CVE-2026-59685. The Apache project publishes source code, not official Windows binaries (that's general industry knowledge), so Windows users usually get httpd from third-party builds or bundled stacks such as XAMPP-style packages. Check whether your provider has shipped a 2.4.69-based build before you mark the issue closed. Updating Windows itself won't patch it.

Section summary: Find out which modules you run, review the risky settings, upgrade to 2.4.69 or your vendor's patched package, and confirm your Windows build actually includes the fix.

Bottom line​

Apache's "nothing important" verdict is reasonable for a default configuration. Few production servers run a default configuration, though. If you run WebDAV, HTTP/2, Digest auth, proxy modules or Apache on Windows, schedule this update for your next maintenance window rather than a far-off quarterly cycle.

 

References

  1. Apache Patched 20 Flaws in HTTP Server. It Rated None of Them Important - H2S Media H2S Media 2026-10-07T07:03:02+00:00
  2. Apache HTTP Server 2.4.69 Fixes 20 Flaws, Including Code Execution Risks mallory.ai
  3. Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project httpd.apache.org