CVE-2026-24072Disclosure(apache / http_server)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache http_server systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user. Users are recommended to upgrade to version 2.4.67, which fixes this issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • http_server

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 9 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 4 mentions (2026-05-04); latest day: 1
  • 9 total mentions across 5 days

Affected systems

Vendors
Products
http_server

Deep dive

Activity timeline9 mentions / 5d
01234Mentions · 2026-05-04: 4Mentions · 2026-05-05: 1Mentions · 2026-05-06: 1Mentions · 2026-05-08: 2Mentions · 2026-05-12: 1Patch / Workaround · 2026-05-04: 1Patch / Workaround · 2026-05-06: 1Patch / Workaround · 2026-05-08: 1Technical Details · 2026-05-04: 4Technical Details · 2026-05-05: 1Technical Details · 2026-05-06: 1Technical Details · 2026-05-08: 2Technical Details · 2026-05-12: 105-0405-0505-0605-0805-12
Signal classification3 categories
Disclosure
555.6%
Patch
333.3%
General
111.1%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-05-044
Disclosure3Patch1
2026-05-051
Disclosure1
2026-05-061
Patch1
2026-05-082
General1Patch1
2026-05-121
Disclosure1
Full discourse9 posts
  • Heart Internet@HeartInternet
    Disclosure

    Security notice for VPS & dedicated server customers. Two Apache HTTP Server vulnerabilities have been disclosed affecting 2.4.66 - including a critical RCE (CVE-2026-23918) and a privilege escalation issue relevant to multi-tenant servers (CVE-2026-24072) 1/2

    Post summary

    The notice announces two Apache HTTP Server vulnerabilities in version 2.4.66, detailing a critical remote code execution and a privilege escalation issue for multi‑tenant servers.

    11012295
    5.9K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Apache HTTP Server の 5 件の脆弱性が FIX:広大な攻撃範囲を持つ RCE など https://iototsecnews.jp/2026/05/05/critical-apache-http-server-flaw-exposes-millions-of-servers-to-rce-attacks/ 今回の脆弱性の主な原因は、メモリ管理の不備や設定の不備にあります。最も深刻な CVE-2026-23918 は、一度解放されたメモリをプログラムが誤って解放してしまう double-free という現象が HTTP/2 の処理中に発生します。これによりメモリの状態が壊れ、攻撃者に操作される恐れがあります。また CVE-2026-24072 では設定ファイルの評価処理の不備から、本来見えないはずのファイルが読み取られてしまいます。他にも CVE-2026-28780 のような容量制限を超えてデータが書き込まれるバッファ・オーバーフローや、CVE-2026-29168 のリソース割り当て制限の不足、CVE-2026-29169 の NULL ポインタ参照など、プログラムが想定外の挙動をする隙が原因となっています。ご利用のチームは、ご注意ください。 #Apache #CVE202623918 #CVE202624072 #CVE202628780 #CVE202629168 #CVE202629169 #HTTPServer #Vulnerability

    Post summary

    Five newly disclosed Apache HTTP Server CVEs are described with technical details (double‑free, buffer overflow, NULL pointer dereference) but no PoC, exploit, or patch information is provided.

    01000152
    491 followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: High-severity flaws in #Apache HTTP Server! #CVE-2026-23918 (CVSS 8.8) is a Double Free bug leading to #RCE. #CVE-2026-24072 (CVSS 8.8) allows local #EoP via mod_rewrite. More info: https://ccb.belgium.be/advisories/warning-multiple-vulnerabilities-apache-http-server-can-lead-remote-code-execution-patch #Patch #Patch #Patch

    Post summary

    A warning about two high‑severity Apache HTTP Server CVEs is posted, with technical details and a link to a patch advisory, but no PoC or evidence of active exploitation is mentioned.

    01000261
    7.2K followersView on X
  • Kazuki Omo@omokazuki
    Patch

    Apache HTTP Serverの脆弱性(Important: CVE-2026-23918, Moderate: CVE-2026-24072, CVE-2026-33006, Low:複数)と2.4.67リリース #sios_tech #security #vulnerability #セキュリティ #脆弱性 #apache #struts https://security.sios.jp/vulnerability/apache-security-vulnerability-20260505/

    Post summary

    The post lists several Apache HTTP Server CVEs and announces the 2.4.67 release, implying that the new version patches these issues.

    00010293
    365 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-24072 An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user… https://www.cve.org/CVERecord?id=CVE-2026-24072

    Post summary

    The post announces a privilege–escalation vulnerability (CVE‑2026‑24072) in Apache HTTP Server 2.4.66 and earlier, allowing local .htaccess authors to read files with httpd user privileges.

    00001183
    57.4K followersView on X
  • OverResearched Intelligence@ORIntelligence
    General

    🔴 Apache HTTP/2 RCE (CVE-2026-23918) & mod_rewrite EoP (CVE-2026-24072) 🟠 PCPJack worm evicts TeamPCP, steals creds 🟠 Akira: 38 new victims (health/mfg/edu) Full brief: https://intel.overresearched.net/2026/05/08/cti-daily-brief/ #Daily #ThreatIntel #InfoSec

    Post summary

    The post lists two new Apache CVEs and notes their general impact types (RCE and EoP) but does not provide evidence of active exploitation, patch details, or exploit code.

    00000100
    7 followersView on X
  • Night☆@MLO_Night
    Patch

    「Apache HTTP Server」にセキュリティ修正 ~リモートコード実行の恐れがある脆弱性/最大深刻度Importantの脆弱性2件を含む計11件を修正したv2.4.67がリリース https://forest.watch.impress.co.jp/docs/news/2106854.html > 「CVE-2026-23918」(リモートコード実行)と「CVE-2026-24072」(権限昇格)はCVSS:3.1のスコアで8.8(HIGH)

    Post summary

    The post announces the release of Apache HTTP Server v2.4.67, which patches two high‑severity vulnerabilities (CVE‑2026‑23918 and CVE‑2026‑24072). It includes technical details like vulnerability types and CVSS scores but does not describe any exploit or ongoing attacks.

    0000086
    2.3K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-24072 An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user… https://www.cve.org/CVERecord?id=CVE-2026-24072 ----- Traducción: CVE-2026-24072 Un … http://infoflow.cloud`

    Post summary

    The snippet announces CVE-2026-24072, describing a privilege escalation flaw in Apache HTTP, without providing PoC, exploitation code, or mitigation details.

    0000068
    75 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-24072 Local Privilege Escalation in Apache HTTP Server 2.4.66 and Earlier https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-24072

    Post summary

    A new local privilege escalation vulnerability (CVE-2026-24072) affecting Apache HTTP Server 2.4.66 and earlier has been disclosed.

    0000073
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachehttp_server---

Explore more