CVE-2026-28780Patch(apache / http_server)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch apache http_server systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to write 4 attacker controlled bytes after the end of a heap based buffer. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122CWE-787

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • http_server

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 13 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 8 signals
  • Technical details provided in 9 signals
  • Disclosure: 4 classified signals
  • Peaked 6d ago at 4 mentions (2026-05-05); latest day: 1
  • 13 total mentions across 7 days

Affected systems

Vendors
Products
http_server

Deep dive

Activity timeline13 mentions / 7d
01234Mentions · 2026-05-05: 4Mentions · 2026-05-06: 3Mentions · 2026-05-08: 1Mentions · 2026-05-11: 2Mentions · 2026-05-12: 1Mentions · 2026-05-25: 1Mentions · 2026-06-26: 1Active Exploitation · 2026-05-06: 1Active Exploitation · 2026-05-11: 1Patch / Workaround · 2026-05-05: 2Patch / Workaround · 2026-05-06: 1Patch / Workaround · 2026-05-08: 1Patch / Workaround · 2026-05-11: 1Patch / Workaround · 2026-05-12: 1Patch / Workaround · 2026-05-25: 1Patch / Workaround · 2026-06-26: 1Technical Details · 2026-05-05: 3Technical Details · 2026-05-06: 1Technical Details · 2026-05-11: 2Technical Details · 2026-05-12: 1Technical Details · 2026-05-25: 1Technical Details · 2026-06-26: 105-0505-0605-0805-1105-1205-2506-26
Signal classification4 categories
Patch
753.8%
Disclosure
430.8%
Active Exploitation
17.7%
General
17.7%
Referenced assets13 URLs
Classification over time
DateTotalLabels
2026-05-054
Disclosure2Patch2
2026-05-063
Active Exploitation1General1Patch1
2026-05-081
Patch1
2026-05-112
Disclosure1Patch1
2026-05-121
Patch1
2026-05-251
Disclosure1
2026-06-261
Patch1
Full discourse13 posts
  • Frank@jedisct1
    Patch

    At least 4 vulnerabilities fixed in Apache 2.4.67 were already independently found by Swival https://github.com/Swival/security-audits/tree/main/apache-httpd#apache-httpd-audit-findings (CVE-2026-33857 is #175, CVE-2026-34032 is #176, CVE-2026-28780 is #174, CVE-2026-33007 is #109)

    Post summary

    The post informs that four CVEs fixed in Apache 2.4.67 were previously identified by Swival, highlighting the antivirus patch, but offers no PoC, exploit, or technical details.

    200301.2K
    17.4K followersView on X
  • Open Source Security mailing list@oss_security
    Patch

    Apache httpd CVE-2026-29169 "fixed in 2.4.66" was an error https://www.openwall.com/lists/oss-security/2026/05/05/12 2 more (11 total): CVE-2026-29168: mod_md unrestricted OCSP response https://www.openwall.com/lists/oss-security/2026/05/05/6 CVE-2026-28780: Buffer overflow in mod_proxy_ajp via ajp_msg_check_header() https://www.openwall.com/lists/oss-security/2026/05/05/9

    Post summary

    The entry lists three Apache httpd CVEs, noting that CVE‑2026‑29169 was fixed in 2.4.66 and providing brief technical details for the remaining vulnerabilities, but it does not mention exploit code or active attacks.

    00030321
    4.7K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🛡️ SUSE-SU-2026:2641-1: 10 CVEs corrigidas no Apache2, incluindo RCE via HTTP/2 (CVE-2026-23918) e estouro de heap no mod_proxy_ajp (CVE-2026-28780). Saiba mais: -> http://tinyurl.com/ae6r983h #SUSE https://t.co/Wi9lcnOT2X

    Post summary

    SUSE announces a security update fixing 10 CVEs in Apache2, notably an RCE via HTTP/2 (CVE-2026-23918) and a heap overflow in mod_proxy_ajp (CVE-2026-28780), urging users to apply the latest patch.

    1000091
    1.5K followersView on X
  • SecAlerts@SecAlertsCo
    Disclosure

    CVE-2026-28780 — Critical 9.8 heap buffer overflow in Apache HTTP Server's mod_proxy_ajp. If your server proxies to a malicious AJP backend, it can trigger RCE. No auth needed. Audit your AJP upstream configs. https://secalerts.co/vulnerability/CVE-2026-28780

    Post summary

    A newly disclosed critical heap buffer overflow (CVE-2026-28780) in Apache HTTP Server’s mod_proxy_ajp can lead to remote code execution via a malicious AJP backend; administrators are urged to audit AJP upstream configurations and apply the vendor patch.

    0000176
    826 followersView on X
  • iototsecnews@iototsecnews
    Patch

    Apache HTTP Server の 5 件の脆弱性が FIX:広大な攻撃範囲を持つ RCE など https://iototsecnews.jp/2026/05/05/critical-apache-http-server-flaw-exposes-millions-of-servers-to-rce-attacks/ 今回の脆弱性の主な原因は、メモリ管理の不備や設定の不備にあります。最も深刻な CVE-2026-23918 は、一度解放されたメモリをプログラムが誤って解放してしまう double-free という現象が HTTP/2 の処理中に発生します。これによりメモリの状態が壊れ、攻撃者に操作される恐れがあります。また CVE-2026-24072 では設定ファイルの評価処理の不備から、本来見えないはずのファイルが読み取られてしまいます。他にも CVE-2026-28780 のような容量制限を超えてデータが書き込まれるバッファ・オーバーフローや、CVE-2026-29168 のリソース割り当て制限の不足、CVE-2026-29169 の NULL ポインタ参照など、プログラムが想定外の挙動をする隙が原因となっています。ご利用のチームは、ご注意ください。 #Apache #CVE202623918 #CVE202624072 #CVE202628780 #CVE202629168 #CVE202629169 #HTTPServer #Vulnerability

    Post summary

    The article reports that five critical Apache HTTP Server CVEs have been fixed, providing detailed technical descriptions of each vulnerability while indicating patch availability.

    01000152
    491 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Unpopular opinion: The cybersecurity industry is selling you dashboards. CVE: CVE-2026-28780 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The post briefly announces CVE-2026-28780, listing its CVSS score and critical severity, but offers no PoC, exploitation details, or mitigation information.

    1000040
    197 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 Apache HTTP Server Alert: CVE-2026-28780 A heap buffer overflow in mod_proxy_ajp could let a malicious AJP backend trigger memory corruption in Apache HTTP Server ≤2.4.66. Upgrade to Apache HTTP Server 2.4.67 ASAP. #Apache #httpd #CVE #CyberSecurity

    Post summary

    The CVE-2026-28780 vulnerability is a heap buffer overflow in Apache HTTP Server's mod_proxy_ajp, potentially causing memory corruption; users are advised to upgrade to version 2.4.67 immediately.

    0001087
    149 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    https://lyrie.ai/research/research/cve-2026-28780-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The linked advisory discusses CVE‑2026‑28780, providing technical details and recommending a patch, with implications of potential active exploitation hinted by the #zerodayattack tag.

    0000016
    188 followersView on X
  • Vulert@vulert_official
    Patch

    🚨 CVE-2026-28780 affects Apache HTTP Server mod_proxy_ajp and could expose servers to serious security risks. Upgrade to 2.4.67+ now. https://vulert.com/vuln-db/CVE-2026-28780 #Apache #CVE #CyberSecurity #Vulert https://t.co/eFSjfnhpl0

    Post summary

    The tweet announces CVE-2026-28780 affecting Apache HTTP Server's mod_proxy_ajp and urges users to upgrade to 2.4.67+.

    0000057
    125 followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    Our CTI team identified a lot of activities targeting Apache HTTP Server (CVE-2026-28780) https://vuldb.com/vuln/361235/cti

    Post summary

    CTI team reports multiple incidents targeting Apache HTTP Server CVE-2026-28780, indicating ongoing exploitation, though specific details and mitigations are absent.

    0000063
    2.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-28780 CVE-2026-28780 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28780

    Post summary

    The post simply lists CVE-2026-28780 and links to a vulnerability database page without providing additional context or actionable information.

    0000052
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-28780 Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malici… https://www.cve.org/CVERecord?id=CVE-2026-28780 ----- Traducción: CVE-2026-28780 des… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-28780 as a heap‑based buffer overflow in Apache’s mod_proxy_ajp, providing minimal technical details but no evidence of exploitation or remediation.

    0000052
    75 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28780 Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malici… https://www.cve.org/CVERecord?id=CVE-2026-28780

    Post summary

    CVE-2026-28780 describes a heap-based buffer overflow in Apache HTTP Server's mod_proxy_ajp that can be exploited via a malicious AJP server; no PoC, exploit code, patch, or active exploitation evidence is provided.

    00000252
    57.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachehttp_server---

Explore more