
BREAKING: Fedora 42 and 43 ship critical AWStats fixes for CVE-2025-63261, closing arbitrary code execution on Apache and IIS via updates 8.0-1 and 8.0-2 released April 10 2026. https://threatcluster.io/cluster/critical-arbitrary-code-execution-vulnerability-in-awstats-f-588c569f
Post summary
Fedora 42/43 released updates 8.0-1 and 8.0-2 that patch CVE‑2025‑63261, closing arbitrary code execution vulnerabilities in AWStats for Apache and IIS.

