CVE-2021-41773General(apache / cloud_backup)

MEDIUMCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch apache cloud_backup systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If CGI scripts are also enabled for these aliased pathes, this could allow for remote code execution. This issue is known to be exploited in the wild. This issue only affects Apache 2.4.49 and not earlier versions. The fix in Apache HTTP Server 2.4.50 was found to be incomplete, see CVE-2021-42013.

5.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2021-11-17. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-22

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cloud_backup
  • fedora
  • http_server
  • instantis_enterprisetrack

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 7 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • General: 3 classified signals
  • Peaked 4d ago at 2 mentions (2026-05-02); latest day: 1
  • 7 total mentions across 6 days

Affected systems

Products
cloud_backupfedorahttp_serverinstantis_enterprisetrack

7 versions affected across 4 products

Deep dive

Activity timeline7 mentions / 6d
01122Mentions · 2026-03-13: 1Mentions · 2026-05-02: 2Mentions · 2026-05-16: 1Mentions · 2026-07-23: 1Mentions · 2026-10-02: 1Mentions · 2026-10-08: 1Active Exploitation · 2026-05-02: 1Active Exploitation · 2026-07-23: 1Patch / Workaround · 2026-07-23: 1Technical Details · 2026-03-13: 1Technical Details · 2026-05-02: 1Technical Details · 2026-05-16: 103-1305-0205-1607-2310-0210-08
Signal classification2 categories
General
360.0%
Active Exploitation
240.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-131
General1
2026-05-022
Active Exploitation1General1
2026-05-161
General1
2026-07-231
Active Exploitation1
Full discourse7 posts
  • Bounty Security@BountySecurity
    General

    🐛 We asked Burp Bounty Pro users: what's your best find? 🔴 Path traversal → server takeover 💀 🔴 SQLi → RCE chain 💉 🔴 Chained SSRF 🌐 🔴 HTTP Request Smuggling 📡 🔴 CVE-2021-41773 in prod 🐛 🔴 £5,000 bounty 💰 Real bugs. Real users. 🔥 Yours? 👇 #BurpBounty https://t.co/hYZjczHNWx

    Post summary

    The tweet highlights various vulnerable paths, including CVE-2021-41773 in production, but does not provide PoC, exploit code, or evidence of active exploitation.

    1171135937.5K
    19.1K followersView on X
  • KEVIntel@kev_intel
    Active Exploitation

    Top KEVs hitting KEVIntel sensors this week: 1. CVE-2021-41773 - 732 2. CVE-2022-47945 - 466 3. CVE-2025-55182 - 337 4. CVE-2026-0770 - 178 5. CVE-2026-63030 - 113 2,497 exploitation attempts from 500 source IPs across our sensors. Patch what attackers are actually exploiting.

    Post summary

    The post lists several CVEs with documented exploitation attempts, confirming that attackers are actively targeting them, and urges patching to mitigate the risk.

    1001094
    41 followersView on X
  • cicada@cicada_HQ
    General

    Attackers build a mental model. “This server runs Apache 2.4.49…” → vulnerable to CVE-2021-41773 → possible LFI → poison logs → get shell → run linpeas → find sudo privesc → escalate to root That’s attack-chain thinking.

    Post summary

    The tweet outlines an attack chain for Apache 2.4.49 LFI (CVE-2021-41773) from log poisoning to privilege escalation, but provides no PoC, exploit code, or patch information.

    1001053
    440 followersView on X
  • Mr_Black111@aka_mr_black
    General

    Every attack got a 400 or 404. Here's why: ✅ No PHP → PHPUnit exploits don't exist ✅ No Apache → CVE-2021-41773 is irrelevant ✅ No .env exposed → secret harvesting finds nothing ✅ Docker API not on host network → container escape blocked ✅ nginx rejects bare IP requests ✅ HTTP → HTTPS forcedSecurity isn't always adding more tools. Sometimes it's having less surface area. #appsec #devops #infosec

    Post summary

    The post references a CVE (CVE-2021-41773) but only notes its irrelevance in a specific environment; it contains no technical details, exploit code, or active exploitation claims. The content is a general countermeasure discussion rather than a focused vulnerability announcement or exploitation report.

    1000046
    47 followersView on X
  • Mr_Black111@aka_mr_black
    Active Exploitation

    In 2 days, my server saw: 🔴 Open proxy testing , SOCKS4, SOCKS5 & HTTP CONNECT attempts to route malicious traffic through my server 🔴 Apache path traversal exploit (CVE-2021-41773) 🔴 PHPUnit RCE , 30+ variants 🔴 .env & .aws/credentials harvesting 🔴 Docker API probe , /containers/json 🔴 MongoDB wire protocol injection 🔴 Mozi botnet IoT malware 🔴 Fake Googlebot headers to bypass filters 🔴 masscan , full internet sweep, my IP flagged as "alive" Plus Shodan, Censys & Palo Alto scanning everything. #infosec #hacking #nginx

    Post summary

    The report documents several real-world attack attempts against the server, including an Apache path traversal exploit, indicating active exploitation of known CVEs.

    1000072
    47 followersView on X
  • DailyCVE@dailycve

    🔴 Apache HTTP Server, Path Traversal, #CVE-2021-41773 (Critical) -DC-Oct2026-2883 https://dailycve.com/apache-http-server-path-traversal-cve-2021-41773-critical-dc-oct2026-2883/

    0000010
    239 followersView on X
  • ♫Why♥Not♪@Python_s_

    NØØT Security Alerts Classification: Critical CVE: CVE-2021-41773 Product: Apache / HTTP Server Summary: VulnCheck reports real-world exploitation activity affecting Apache / HTTP Server. Evidence: Public PoC/exploit available; Ransomware use confirmed; Active exploitation reported; Severe impact class; Live exploitation observed by VulnCheck canaries Impact: The vulnerability is associated with ransomware activity and may contribute to compromise of exposed systems. Action: Prioritize vendor remediation, identify exposed affected systems, and investigate for evidence of exploitation when applicable. Date: 29 Sep 2021 Source: https://vulncheck.com/xdb/4641bb9539f4 #NØØT #CyberSecurity #InfoSec #ThreatIntelligence #CyberThreats #CVE #CyberDefense #Apache #HTTPServer #CVE_2021_41773 #ActiveExploitation #Exploit #Ransomware #RansomwareAttack

    0000066
    226 followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
Appapachehttp_server2.4.49--
OSfedoraprojectfedora34--
OSfedoraprojectfedora35--
Appnetappcloud_backup---
Apporacleinstantis_enterprisetrack17.1--
Apporacleinstantis_enterprisetrack17.2--
Apporacleinstantis_enterprisetrack17.3--

Explore more