Frank[verified]@jedisct1Patch
The post informs that four CVEs fixed in Apache 2.4.67 were previously identified by Swival, highlighting the antivirus patch, but offers no PoC, exploit, or technical details.
Lyrie.ai[verified]@lyrie_aiDisclosure
The post briefly announces CVE-2026-28780, listing its CVSS score and critical severity, but offers no PoC, exploitation details, or mitigation information.
Upwind Security MDR[verified]@UpwindMDRPatch
The CVE-2026-28780 vulnerability is a heap buffer overflow in Apache HTTP Server's mod_proxy_ajp, potentially causing memory corruption; users are advised to upgrade to version 2.4.67 immediately.
Lyrie.ai[verified]@lyrie_aiPatch
The linked advisory discusses CVE‑2026‑28780, providing technical details and recommending a patch, with implications of potential active exploitation hinted by the #zerodayattack tag.
Open Source Security mailing list@oss_securityPatch
The entry lists three Apache httpd CVEs, noting that CVE‑2026‑29169 was fixed in 2.4.66 and providing brief technical details for the remaining vulnerabilities, but it does not mention exploit code or active attacks.
Ferramentas Linux@Cezar_H_LinuxPatch
SUSE announces a security update fixing 10 CVEs in Apache2, notably an RCE via HTTP/2 (CVE-2026-23918) and a heap overflow in mod_proxy_ajp (CVE-2026-28780), urging users to apply the latest patch.
SecAlerts@SecAlertsCoDisclosure
A newly disclosed critical heap buffer overflow (CVE-2026-28780) in Apache HTTP Server’s mod_proxy_ajp can lead to remote code execution via a malicious AJP backend; administrators are urged to audit AJP upstream configurations and apply the vendor patch.
iototsecnews@iototsecnewsPatch
The article reports that five critical Apache HTTP Server CVEs have been fixed, providing detailed technical descriptions of each vulnerability while indicating patch availability.