CVE-2021-42013Disclosure(apache / cloud_backup)

LOWCVSS 9.8 · CRITICALCISA KEV

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If CGI scripts are also enabled for these aliased pathes, this could allow for remote code execution. This issue only affects Apache 2.4.49 and Apache 2.4.50 and not earlier versions.

2.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2021-11-17. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cloud_backup
  • fedora
  • http_server
  • instantis_enterprisetrack

Threat summary

  • Public PoC is present in monitored signal
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-03-10); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Products
cloud_backupfedorahttp_serverinstantis_enterprisetrackjd_edwards_enterpriseone_toolssecure_backup

8 versions affected across 6 products

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-03-10: 1Mentions · 2026-07-12: 1Mentions · 2026-09-06: 1Mentions · 2026-10-05: 1PoC Mentioned / Linked · 2026-07-12: 1Technical Details · 2026-03-10: 1Technical Details · 2026-07-12: 103-1007-1209-0610-05
Signal classification3 categories
Disclosure
133.3%
PoC
133.3%
General
133.3%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-03-101
Disclosure1
2026-07-121
PoC1
2026-09-061
General1
Full discourse4 posts
  • Huntback.io@Huntbackio

    Their job against us isn't map scraping. It's commodity mass-exploitation: • PHPUnit CVE-2017-9841 (64) • F5 BIG-IP CVE-2023-46747 • Apache CVE-2021-42013 • NetScaler SAML, PHP-CGI UAs: spoofed iPhone + Mac Chrome, libredtail-http. Nothing announces itself honestly.

    1000027
    43 followersView on X
  • Christian B.@kimocoder
    General

    I got something better than wpscan and CVE-2021-42013 related anyways - from here an enumeration or attack will result in server responding in extensive defensive measures 😄

    Post summary

    The post references CVE-2021-42013 and claims to have a better tool than WPScan, but it offers no concrete details, PoC, or actionable information.

    00010161
    4.9K followersView on X
  • r0otk3r@r0otk3r
    PoC

    🚨 CVE-2021-42013: Critical 9.8 CVSS Apache HTTP Server Path Traversal & RCE https://www.youtube.com/watch?v=iAadU7OEuqk #Cybersecurity #Infosec #AppSec #RCE #PathTraversal #Apache #Httpd #CVE202142013 #PoC #EthicalHacking #BugBounty #PatchNow https://t.co/vA7zQqj27y

    Post summary

    The text announces CVE-2021-42013, includes a link to a PoC video, and notes its critical RCE/path‑traversal nature, but does not provide exploit code or evidence of active exploitation.

    0001068
    43 followersView on X
  • r0otk3r@r0otk3r
    Disclosure

    CVE-2021-42013: How "Path Traversal" leads to Unauth RCE in Apache HTTP Server.🚨 #CVE202142013 #CyberSecurity #CISA #Infosec #BugBounty #RCE #Pentesting #Apache https://t.co/vXpCwmQEbS

    Post summary

    The tweet announces CVE‑2021‑42013, describing how a path‑traversal vulnerability in Apache HTTP Server can lead to unauthenticated remote code execution.

    0001038
    42 followersView on X
CPE platform detail10 entries

10 of 10 entries

PartVendorProductVersionTarget SWTarget HW
Appapachehttp_server2.4.49--
Appapachehttp_server2.4.50--
OSfedoraprojectfedora34--
OSfedoraprojectfedora35--
Appnetappcloud_backup---
Apporacleinstantis_enterprisetrack17.1--
Apporacleinstantis_enterprisetrack17.2--
Apporacleinstantis_enterprisetrack17.3--
Apporaclejd_edwards_enterpriseone_tools---
Apporaclesecure_backup---

Explore more