CVE-2026-33006General(apache / http_server)

LOWCVSS 4.8 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch apache http_server systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A timing attack against mod_auth_digest in Apache HTTP Server 2.4.66 allows a bypass of Digest authentication by a remote attacker. Users are recommended to upgrade to version 2.4.67, which fixes this issue.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-208

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • http_server

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-05-04); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
http_server

Deep dive

Activity timeline6 mentions / 3d
01223Mentions · 2026-05-04: 3Mentions · 2026-05-11: 2Mentions · 2026-05-28: 1PoC Mentioned / Linked · 2026-05-28: 1Patch / Workaround · 2026-05-04: 1Patch / Workaround · 2026-05-11: 2Technical Details · 2026-05-04: 105-0405-1105-28
Signal classification4 categories
General
233.3%
Patch
233.3%
Disclosure
116.7%
Exploit
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-043
Disclosure1General2
2026-05-112
Patch2
2026-05-281
Exploit1
Full discourse6 posts
  • Gabriel Odusanya@gabbytech01
    Exploit

    Running some vuln scan on mobile with Termux is lowkey fire 🔥 Caught multiple EXPLOIT bangers already: EA6ADD14-D80B-5DC2-9991-1F9663E2D09F • CVE-2026-33006 • SSV:87152 • PacketStorm:127563 Didn't know termux is fun to use, could run some exploits too by the way https://t.co/db1hlXtMtE

    Post summary

    The post emphasizes Termux’s capability to discover and run exploits, mentioning CVE‑2026‑33006 and providing a link likely pointing to exploit code, but it offers no patch details or evidence of active exploitation.

    21184946
    6.6K followersView on X
  • Lucian Nitescu 🇷🇴@LucianNitescu
    General

    My first experience with web services was through Apache httpd, and this year I discovered my first CVE in that very same service. It was published today as CVE-2026-33006. https://www.cve.org/CVERecord?id=CVE-2026-33006 https://t.co/nuckXckgOH

    Post summary

    The tweet announces the publication of CVE-2026-33006 for Apache httpd but provides no technical details or exploitation information.

    12010330
    948 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-httpd24 モジュール更新情報 2.4.67-1 https://kusanagi.tokyo/releases/24495/ KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 httpd24 2.4.67-1 この更新には脆弱性(CVE-2026-34059, CVE-2026-34032, CVE-2026-33857, CVE-2026-33523, CVE-2026-33007, CVE-2026-33006, CVE-2026-...

    Post summary

    The post announces a kusanagi-httpd24 module update that patches several CVEs, but offers no PoC, exploit code, or detailed technical vulnerability information.

    0101066
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-httpd24 モジュール更新情報 2.4.67-1.el9 https://kusanagi.tokyo/releases/24489/ KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 httpd24 2.4.67-1.el9 この更新には脆弱性(CVE-2026-34059, CVE-2026-34032, CVE-2026-33857, CVE-2026-33523, CVE-2026-33007, CVE-2026-33006, C...

    Post summary

    The Kusanagi httpd24 module was updated to version 2.4.67-1.el9, addressing several CVEs—a clear patch notice. No exploit or PoC information is provided.

    0101062
    200 followersView on X
  • Kazuki Omo@omokazuki
    Disclosure

    Apache HTTP Serverの脆弱性(Important: CVE-2026-23918, Moderate: CVE-2026-24072, CVE-2026-33006, Low:複数)と2.4.67リリース #sios_tech #security #vulnerability #セキュリティ #脆弱性 #apache #struts https://security.sios.jp/vulnerability/apache-security-vulnerability-20260505/

    Post summary

    The article announces several new Apache HTTP Server vulnerabilities identified by CVE numbers, notes the severity levels, and references the 2.4.67 release as a patch.

    00010293
    365 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-33006 Timing Attack Authentication Bypass in Apache HTTP Server 2.4.66 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33006

    Post summary

    The entry announces CVE-2026-33006, noting a timing‑attack authentication bypass in Apache HTTP Server 2.4.66, but provides no evidence of PoCs, exploits, active attacks, or patches.

    0000055
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachehttp_server---

Explore more