CVE-2026-33267Exploit(apache / traffic_server)

MEDIUMCVSS 9.1 · CRITICAL

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Patch apache traffic_server systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.14, from 10.1.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • traffic_server

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 3 signals
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
traffic_server

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-14: 3PoC Mentioned / Linked · 2026-08-14: 3Exploit Tool / Code · 2026-08-14: 3Patch / Workaround · 2026-08-14: 1Technical Details · 2026-08-14: 308-14
Signal classification1 categories
Exploit
3100.0%
Referenced assets1 URL
By indicator
Full discourse3 posts
  • dbugs@ptdbugs
    Exploit

    A PoC/exploit has been discovered for vulnerability CVE-2026-33267 Vendor: Apache Software Foundation Product: Apache Traffic Server Description: Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.14, from 10.1.0 through 10.1.3. Link: https://github.com/boreas37/cve-2026-33267-poc #dbugs_vuln

    Post summary

    A PoC/exploit for CVE-2026-33267 has been released with a GitHub repository containing the code, but no active exploitation or patch information is mentioned.

    04030103.9K
    3.6K followersView on X
  • dbugs@ptdbugs
    Exploit

    🔔 A PoC/exploit has been discovered for vulnerability CVE-2026-33267 Vendor: Apache Software Foundation Product: Apache Traffic Server Description: Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.14, from 10.1.0 through 10.1.3. Link: https://github.com/boreas37/cve-2026-33267-poc #dbugs_vuln

    Post summary

    A PoC and functional exploit for CVE-2026-33267 targeting Apache Traffic Server has been released via GitHub; no active exploitation or vendor patch information is provided.

    0201551.7K
    3.6K followersView on X
  • ThreatWire@ThreatWire_
    Exploit

    🚨 PoC RELEASED: Public exploit code is now available for CVE-2026-33267, a critical Apache Traffic Server improper input validation flaw. The vulnerability can be exploited remotely without authentication and may allow attackers to spoof internal ATS metadata, potentially affecting routing, caching and access controls. Affected: 9.2.0–9.2.14 & 10.1.0–10.1.3. Upgrade to 9.2.15 or 10.1.4. 🔗 https://github.com/boreas37/cve-2026-33267-poc #Apache #TrafficServer #CVE #PoC #CyberSecurity #Infosec

    Post summary

    Public exploit code for CVE-2026-33267, an improper input validation flaw in Apache Traffic Server, has been released on GitHub and can be used to spoof internal ATS metadata; the vulnerability is mitigated by upgrading to 9.2.15 or 10.1.4.

    00020367
    1.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachetraffic_server---

Explore more