CVE-2026-23918Patch(apache / http_server)

CRITICALCVSS 8.8 · HIGH

Exploitation observed; activity peaked at 70 mentions and remains active

Immediate actions

  • Patch apache http_server systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

9.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-415CWE-1341

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • http_server

Threat summary

  • Active exploitation appears in 5 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 228 mentions across 26 observed days

What's happening

  • Active exploitation reported across 5 signals
  • Exploit tool or code specified in 16 signals
  • PoC mentioned or linked in 34 signals
  • Patch or workaround mentioned in 114 signals
  • Technical details provided in 187 signals
  • Disclosure: 73 classified signals
  • General: 31 classified signals
  • Peaked 24d ago at 70 mentions (2026-05-05); latest day: 1
  • 228 total mentions across 26 days

Affected systems

Vendors
Products
http_server

1 version affected across 1 product

Deep dive

Activity timeline228 mentions / 26d
018355370Mentions · 2026-05-04: 3Mentions · 2026-05-05: 70Mentions · 2026-05-06: 63Mentions · 2026-05-07: 15Mentions · 2026-05-08: 15Mentions · 2026-05-09: 10Mentions · 2026-05-10: 4Mentions · 2026-05-11: 7Mentions · 2026-05-12: 4Mentions · 2026-05-13: 4Mentions · 2026-05-14: 1Mentions · 2026-05-17: 2Mentions · 2026-05-18: 1Mentions · 2026-05-19: 1Mentions · 2026-06-03: 8Mentions · 2026-06-04: 3Mentions · 2026-06-12: 1Mentions · 2026-06-13: 4Mentions · 2026-06-15: 4Mentions · 2026-06-25: 2Mentions · 2026-06-26: 1Mentions · 2026-06-27: 1Mentions · 2026-06-28: 1Mentions · 2026-07-01: 1Mentions · 2026-08-12: 1Mentions · 2026-09-29: 1PoC Mentioned / Linked · 2026-05-05: 6PoC Mentioned / Linked · 2026-05-06: 8PoC Mentioned / Linked · 2026-05-07: 1PoC Mentioned / Linked · 2026-05-08: 2PoC Mentioned / Linked · 2026-05-09: 4PoC Mentioned / Linked · 2026-05-11: 4PoC Mentioned / Linked · 2026-05-12: 2PoC Mentioned / Linked · 2026-05-13: 2PoC Mentioned / Linked · 2026-05-14: 1PoC Mentioned / Linked · 2026-05-19: 1PoC Mentioned / Linked · 2026-06-04: 3Exploit Tool / Code · 2026-05-05: 3Exploit Tool / Code · 2026-05-06: 1Exploit Tool / Code · 2026-05-07: 1Exploit Tool / Code · 2026-05-08: 1Exploit Tool / Code · 2026-05-09: 2Exploit Tool / Code · 2026-05-11: 3Exploit Tool / Code · 2026-05-12: 2Exploit Tool / Code · 2026-05-14: 1Exploit Tool / Code · 2026-06-04: 2Active Exploitation · 2026-05-05: 3Active Exploitation · 2026-05-07: 1Active Exploitation · 2026-05-08: 1Patch / Workaround · 2026-05-04: 2Patch / Workaround · 2026-05-05: 34Patch / Workaround · 2026-05-06: 36Patch / Workaround · 2026-05-07: 6Patch / Workaround · 2026-05-08: 11Patch / Workaround · 2026-05-09: 3Patch / Workaround · 2026-05-10: 1Patch / Workaround · 2026-05-11: 3Patch / Workaround · 2026-05-12: 1Patch / Workaround · 2026-05-13: 2Patch / Workaround · 2026-05-14: 1Patch / Workaround · 2026-05-17: 1Patch / Workaround · 2026-05-18: 1Patch / Workaround · 2026-05-19: 1Patch / Workaround · 2026-06-03: 2Patch / Workaround · 2026-06-04: 1Patch / Workaround · 2026-06-12: 1Patch / Workaround · 2026-06-13: 4Patch / Workaround · 2026-06-26: 1Patch / Workaround · 2026-06-27: 1Patch / Workaround · 2026-09-29: 1Technical Details · 2026-05-04: 3Technical Details · 2026-05-05: 60Technical Details · 2026-05-06: 48Technical Details · 2026-05-07: 10Technical Details · 2026-05-08: 12Technical Details · 2026-05-09: 8Technical Details · 2026-05-10: 3Technical Details · 2026-05-11: 7Technical Details · 2026-05-12: 3Technical Details · 2026-05-13: 3Technical Details · 2026-05-14: 1Technical Details · 2026-05-17: 2Technical Details · 2026-05-18: 1Technical Details · 2026-05-19: 1Technical Details · 2026-06-03: 8Technical Details · 2026-06-04: 3Technical Details · 2026-06-12: 1Technical Details · 2026-06-13: 3Technical Details · 2026-06-15: 4Technical Details · 2026-06-25: 1Technical Details · 2026-06-26: 1Technical Details · 2026-06-27: 1Technical Details · 2026-06-28: 1Technical Details · 2026-08-12: 1Technical Details · 2026-09-29: 105-0405-0605-0805-1005-1205-1405-1806-0306-1206-1506-2606-2808-1209-29
Signal classification8 categories
Patch
9541.7%
Disclosure
7332.0%
General
3113.6%
PoC
156.6%
Exploit
73.1%
Active Exploitation
52.2%
Referenced assets136 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-043
General1Patch2
2026-05-0570
Active Exploitation3Disclosure25Exploit2General8Patch29PoC3
2026-05-0663
Disclosure17Disclosures1General12Patch31PoC2
2026-05-0715
Active Exploitation1Disclosure5False Positive1General3Patch5
2026-05-0815
Active Exploitation1Disclosure2Exploit1General1Patch9PoC1
2026-05-0910
Disclosure5General1Patch1PoC3
2026-05-104
Disclosure2General1Patch1
2026-05-117
Disclosure2Exploit2Patch1PoC2
2026-05-124
General1Patch1PoC2
2026-05-134
Disclosure2Patch2
2026-05-141
Exploit1
2026-05-172
Disclosure1Patch1
2026-05-181
Patch1
2026-05-191
Patch1
2026-06-038
Disclosure5General1Patch2
2026-06-043
Exploit1PoC2
2026-06-121
Patch1
2026-06-134
Patch4
2026-06-154
Disclosure4
2026-06-252
Disclosure1General1
2026-06-261
Patch1
2026-06-271
Patch1
2026-06-281
Disclosure1
2026-07-011
General1
2026-08-121
Disclosure1
2026-09-291
Patch1
Full discourse20 posts
  • striga@striga_ai
    Exploit

    PoCs for Apache Tomcat Unauth RCE (CVE-2026-34486) and Apache httpd Pre-auth RCE (CVE-2026-23918) are now public on our Github. Tomcat exploit is fully reliable. httpd chain works in a controlled lab setup with a known info leak. https://github.com/striga-ai/CVE-2026-34486 https://github.com/striga-ai/CVE-2026-23918

    Post summary

    PoCs for CVE-2026-34486 (Apache Tomcat) and CVE-2026-23918 (Apache httpd) are publicly available on GitHub, with functional exploit code confirmed for both.

    4180673351795.3K
    536 followersView on X
  • H4x0r.DZ 🇰🇵@h4x0r_dz
    PoC

    Reproducing a Double Free RCE in Apache CVE-2026-23918 on the most used software on the internet with one prompt that costs like $0.001 via DeepSeek is scary as hell. Now, anyone with zero knowledge can hack the internet. (Not default installs though. You need mod_http2 enabled.)

    Post summary

    The post highlights a reproducible Double Free RCE in Apache’s mod_http2 module that can be triggered with a simple prompt, underscoring the vulnerability’s exploitability even though no code or live attacks are reported.

    21109864438285.5K
    81.3K followersView on X
  • Mohammad@Linuxmaster14
    General

    این فیلترنت پدرسگو وصل نکنید تا کل سرورا و سایتای داخلی عین پشمک هک بشن. CVE-2026-23918

    Post summary

    The text only warns against connecting a particular firewall that could expose servers to the CVE-2026-23918 vulnerability, without providing any additional technical or exploit information.

    91205235544.5K
    4.4K followersView on X
  • striga@striga_ai
    Exploit

    CVE-2026-23918 - a pre-auth RCE in Apache httpd's mod_http2, found by Striga during our open-source research. The bug triggers on a single HTTP/2 connection sending HEADERS followed by RST_STREAM with a non-zero error code. Two nghttp2 callbacks both push the same stream pointer onto the cleanup array, and the second pool_destroy hits already-freed memory. We built a working RCE on x86_64 using mmap reuse and Apache's scoreboard memory as a stable container for fake cleanup structures. Affects Apache httpd 2.4.66 with mod_http2 and a multi-threaded MPM. Full technical writeup coming soon. https://www.cve.org/CVERecord?id=CVE-2026-23918 https://httpd.apache.org/security/vulnerabilities_24.html

    Post summary

    A pre‑auth remote code execution vulnerability (CVE-2026-23918) in Apache httpd's mod_http2 has a working exploit demonstrated and technical details provided, but no evidence of active exploitation or patch information.

    450224912433.4K
    537 followersView on X
  • yousukezan@yousukezan
    PoC

    Apache Tomcat の認証なし RCE (CVE-2026-34486) および Apache httpd の認証前 RCE (CVE-2026-23918) の PoC が、GitHub で公開されている。 CVE-2026-34486は、クラスタリング機能であるTribesのEncryptInterceptorにおいて、暗号化処理の失敗時に通信を許可してしまう「fail-open」動作が原因である。本来は暗号化されるべき通信が未検証のまま受け入れられ、Javaのデシリアライズ処理と組み合わさることで、認証なしでリモートコード実行(RCE)が可能となる重大な問題となっている。 影響を受けるのはTomcat 9.0.116以降、10.1.53以降、11.0.19以降で、修正版はそれぞれ9.0.117、10.1.54、11.0.21で提供されている。 CVE-2026-23918は、HTTP/2機能を提供するmod_http2モジュールにおけるダブルフリー(double-free)バグで、ストリーム終了処理中のメモリ管理不備が原因となっている。これにより、認証前の段階でリモートコード実行(RCE)が可能になる重大な問題である。影響を受けるのは、マルチスレッド型MPM(event/worker)を使用したhttpd 2.4.66であり、バージョン2.4.67で修正されている。 https://github.com/striga-ai/CVE-2026-34486 https://github.com/striga-ai/CVE-2026-23918

    Post summary

    The post announces publicly available Proof‑of‑Code links for two authentication‑bypass RCE CVEs in Tomcat and httpd, details the technical mechanisms behind the flaws, and lists the patched releases.

    164322813119.8K
    14.5K followersView on X
  • Ali Sünbül@_xeloxa
    PoC

    Wrote a PoC exploit for CVE-2026-23918, a recently patched double-free bug in Apache's mod_http2. Send a HEADERS frame followed by RST_STREAM, and the server tries to free the same pointer twice. Result: SIGSEGV. 🧵 https://t.co/86UVkZ7OFB

    Post summary

    The author released a proof‑of‑concept exploit for CVE‑2026‑23918, demonstrating a double‑free in Apache’s mod_http2, and notes the flaw has been patched.

    32421547912.2K
    67 followersView on X
  • Hunter@HunterMapping
    Disclosure

    🚨Alert🚨 CVE-2026-23918 : Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. 📊 3.8K+ Services are found on the http://hunter.how yearly. 🔗Hunter Link:https://test-how.hunter.qianxin-inc.cn/list?searchValue=product.name%3D%22Apache%20HTTP%20Server%22%26%26product.name%3D%22HTTP%2F2%22 👇Query HUNTER : http://product.name="Apache HTTP Server"&&http://product.name="HTTP/2" 📰Refer:https://thehackernews.com/2026/05/critical-apache-http2-flaw-cve-2026.html https://httpd.apache.org/security/vulnerabilities_24.html #hunterhow #infosec #infosecurity #OSINT #Vulnerability

    Post summary

    The post announces the discovery of CVE-2026-23918, a Double Free that could lead to remote code execution in Apache HTTP Server’s HTTP/2 implementation, and provides links to vendor resources and affected service listings.

    23701376016.3K
    26.0K followersView on X
  • The Hacker News@TheHackersNews
    Patch

    🚨 Apache patches CVE-2026-23918 (CVSS 8.8) in HTTP Server 2.4.66. The HTTP/2 double-free flaw can trigger DoS and potentially enable remote code execution via crafted requests. Fixed in 2.4.67. Details here: https://thehackernews.com/2026/05/critical-apache-http2-flaw-cve-2026.html

    Post summary

    Apache has released a patch for CVE‑2026‑23918, fixing a double‑free HTTP/2 flaw that could cause DoS or remote code execution. The advisory provides technical details and a CVSS score of 8.8.

    64851492740.6K
    1.8M followersView on X
  • The Hacker News@TheHackersNews
    Exploit

    How easy is CVE-2026-23918 to trigger? 🔸 One TCP connection. 🔸 Two frames. 🔸 HEADERS + immediate RST_STREAM (non-zero error code). That’s it → double-free in mod_http2, worker crashes. Researchers built a working RCE PoC using Apache’s fixed scoreboard + mmap allocator (default on Debian & official Docker). If you’re on 2.4.66 with mod_http2 + threaded MPM: patch to 2.4.67 now. (prefork MPM is safe)

    Post summary

    CVE‑2026‑23918 is a double‑free flaw in Apache mod_http2 that can be triggered with a minimal packet sequence; researchers provided a working RCE PoC and a patch recommendation.

    22211285022.5K
    1.8M followersView on X
  • Nicolas Krassas@Dinosn
    Patch

    Critical Apache HTTP Server RCE (CVE-2026-23918) - Millions of Servers Potentially Exposed. Patches released https://thecybersecguru.com/news/apache-rce-vulnerability-cve-2026-23918/

    Post summary

    The article reports a critical RCE vulnerability in Apache HTTP Server (CVE-2026-23918) that may affect many servers, noting that patches are now available.

    124293487.7K
    158.1K followersView on X
  • Netlas.io@Netlas_io
    Disclosure

    CVE-2026-23918 and other: Several vulnerabilities in Apache HTTP Server, up to 8.8 rating 🔥 Several vulnerabilities in Apache HTTP Server allow attacker to achieve RCE on the server, to bypass authentication, or escalate privileges. 👉 https://nt.ls/I4fYP

    Post summary

    Several Apache HTTP Server CVEs are disclosed that enable remote code execution, authentication bypass, and privilege escalation, underscoring their severity though no specific patches, PoCs, or evidence of active exploitation are mentioned.

    5234626152.6K
    7.6K followersView on X
  • ZoomEye@zoomeye_team
    Disclosure

    🚨 CVE-2026-23918: Apache HTTP Server: http2: double free and possible RCE on early reset Critical Vulnerability Alert! Apache httpd is affected by CVE-2026-23918. Full Vulnerability Details & Analysis at DarkEye: 🔗 https://darkeye.org/vuln/cve/CVE-2026-23918 🔍 Identify Targets via ZoomEye: Filter: vul.cve="CVE-2026-23918" Search Dork: app="Apache httpd" Exposure: 588.5m instances identified globally. ZoomEye Search Link: 👉 https://www.zoomeye.ai/searchResult?q=YXBwPSJBcGFjaGUgaHR0cGQi&t=all&utm_source=twitter&utm_medium=social&utm_campaign=cve_ops_20260812 🚀 ZoomEye continues to expand its AI ecosystem. Today we're introducing WebMCP support, enabling compatible AI agents to discover and invoke ZoomEye tools directly from the website. Explore our AI ecosystem: 1⃣ WebMCP 2⃣ MCP Server →(http://github.com/zoomeye-ai/mcp…) 3⃣ AI Skills →(http://ai.trusttools.cn/skills/zoomeye…) Building an AI-native cybersecurity platform. #Infosec #CyberSecurity #ZoomEye #DarkEye

    Post summary

    The tweet outlines the discovery of CVE‑2026‑23918, a double‑free flaw that could allow remote code execution in Apache HTTP Server, and provides a link to a detailed analysis page, but it does not report any active exploitation, patch, or PoC.

    227074355.6K
    12.7K followersView on X
  • Syntax Teror@syntax_teror
    General

    تبریک میگم، بگایی جدید Critical Apache HTTP Server RCE (CVE-2026-23918)

    Post summary

    The post announces a new critical Apache HTTP Server RCE vulnerability (CVE-2026-23918), but provides no further technical details, PoC, exploit code, patch, or evidence of active exploitation.

    251721614.1K
    788 followersView on X
  • Hamed Bidi@hamedbd
    Patch

    Apache HTTP Server: آپاچی در نسخه ۲.۴.۶۷ آسیب‌پذیری خطرناک CVE-2026-23918 (امتیاز CVSS ۸.۸) را رفع کرد که امکان اجرای کد از راه دور و اختلال در سرویس (DoS) از طریق HTTP/2 را ایجاد می‌کرد. وب‌سرورهای آپاچی بدون این پچ در معرض کنترل کامل از راه دور قرار دارند. ۷/۱۴

    Post summary

    Apache HTTP Server 2.4.67 has applied a patch for CVE-2026-23918, fixing a critical RCE/DoS flaw; servers not updated remain fully remote‑takeover‑vulnerable.

    1008602.8K
    18.5K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Apache releases v2.4.67 to fix an HTTP/2 Double Free RCE (CVE-2026-23918) and auth bypasses. Millions of servers are affected—upgrade your infrastructure now! #Apache #RCE #CyberSecurity #InfoSec #WebServer #PatchAlert #SysAdmin #CVE202623918 https://securityonline.info/apache-http-server-rce-vulnerability-cve-2026-23918-patch-2-4-67/ https://t.co/x8ocvShYfi

    Post summary

    The tweet announces the release of Apache HTTP Server 2.4.67, which fixes CVE-2026-23918—a double free Remote Code Execution vulnerability in HTTP/2, and urges users to upgrade.

    317047204.0K
    12.5K followersView on X
  • TRSiber | Cyber Security@trsiberyazilim
    Patch

    Apache HTTP Server için kritik güvenlik açığı yayınlandı. ☑️ CVE-2026-23918 açığı, HTTP/2 üzerinden servis çökmesine ve potansiyel uzaktan kod çalıştırmaya yol açabiliyor. Apache 2.4.66 kullanan sistemlerin acilen 2.4.67’ye güncellenmesi öneriliyor. Detaylar 👇 🔗https://www.trsiber.net/siber-dunya-haberleri/53-apache-http-server-cve-2026-23918-acigi-http-2-uzerinden-kritik-rce-riski-2026-guncel #Apache #CyberSecurity #SiberGüvenlik #Linux #HTTP2 #Infosec #Teknoloji #YapayZeka #Gündem #SonDakika #çarşamba

    Post summary

    The post announces the critical CVE-2026-23918 in Apache HTTP Server, highlights potential remote code execution via HTTP/2, and urges users running 2.4.66 to immediately upgrade to 2.4.67.

    020810443
    316 followersView on X
  • CiberBaur@BotBauR
    Patch

    Acaba de confirmarse: una vulnerabilidad crítica en el servidor HTTP de Apache (CVE-2026-23918) permite a los atacantes realizar un ataque de denegación de servicio (DoS) y potencialmente ejecutar código remoto (RCE). El equipo descubrió esta vulnerabilidad en el protocolo HTTP/2, que afecta a versiones del Apache HTTP Server 2.4.57-2.4.62 con mod_http2 habilitado. La explotación requiere solo una solicitud HTTP/2 válida desde un cliente no autenticado. La vulnerabilidad ha sido calificada con un CVSS score de 8.8, lo que la convierte en una amenaza crítica. Si usas Apache HTTP Server 2.4.57-2.4.62 con mod_http2, es crucial que actualices a la versión más reciente lo antes posible. La Apache Software Foundation ha lanzado parches para abordar esta vulnerabilidad. ¿Estás en riesgo? Revisa esto: actualiza tu servidor y verifica los logs de actividad para detectar posibles intentos de explotación. https://thehackernews.com/2026/05/critical-apache-http2-flaw-cve-2026.html

    Post summary

    A critical DoS/RCE flaw (CVE‑2026‑23918) affecting Apache HTTP Server 2.4.57‑2.4.62 with mod_http2 is confirmed; patches are available and users are urged to update immediately.

    114244202.6K
    399 followersView on X
  • OS開発者@hacker_infra
    Patch

    CVE-2026-23918 が重大度が高いけど、この書き方だとApache2.4.66までの全バージョンが影響を受けるような印象があるかな 正確には2.4.66のみ影響をうける。 緩和策はh2をやめればいいだけか https://securityonline.info/cve-watchtower/?cve_detail=CVE-2026-23918

    Post summary

    The post identifies CVE-2026-23918 as affecting only Apache 2.4.66 and recommends disabling HTTP/2 (h2) as a workaround.

    010035155.3K
    2.8K followersView on X
  • elhacker.NET@elhackernet
    Disclosure

    @The_Cyber_News CVE-2026-23918 only affects Apache HTTP Server: 2.4.66 not older versions Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. https://www.openwall.com/lists/oss-security/2026/05/04/19

    Post summary

    CVE-2026-23918 is disclosed as a double free and possible RCE in Apache HTTP Server 2.4.66 via the HTTP/2 protocol.

    1503567.8K
    140.9K followersView on X
  • 𝗚𝘂𝗶𝗹𝗹𝗲𝗿𝗺𝗼 💾🌍 (oldoldstable)@GuillermoVersus
    Patch

    Debian ha parcheado ya hasta el Apache de la versión bullseye para solucionar la vulnerabilidad CVE-2026-23918 . 👌💪 ¡Genial! https://t.co/plEpjtDJVx

    Post summary

    Debian has released a patch for Apache in the bullseye release to address CVE-2026-23918. No proof of concept, exploit, or evidence of active exploitation is mentioned.

    1612892.2K
    1.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachehttp_server2.4.66--

Explore more