CVE-2026-33857Patch(apache / http_server)

LOWCVSS 5.3 · MEDIUM

Exploit discussion active in current signal (4 latest mentions)

Immediate actions

  • Patch apache http_server systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Out-of-bounds Read vulnerability in mod_proxy_ajp of Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • http_server

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked at 4 mentions on most recent observed day (2026-05-11)
  • 7 total mentions across 3 days

Affected systems

Vendors
Products
http_server

Deep dive

Activity timeline7 mentions / 3d
01234Mentions · 2026-05-04: 2Mentions · 2026-05-05: 1Mentions · 2026-05-11: 4PoC Mentioned / Linked · 2026-05-05: 1Patch / Workaround · 2026-05-04: 2Patch / Workaround · 2026-05-05: 1Patch / Workaround · 2026-05-11: 4Technical Details · 2026-05-04: 205-0405-0505-11
Signal classification2 categories
Patch
685.7%
Disclosure
114.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-05-042
Disclosure1Patch1
2026-05-051
Patch1
2026-05-114
Patch4
Full discourse7 posts
  • Frank@jedisct1
    Patch

    At least 4 vulnerabilities fixed in Apache 2.4.67 were already independently found by Swival https://github.com/Swival/security-audits/tree/main/apache-httpd#apache-httpd-audit-findings (CVE-2026-33857 is #175, CVE-2026-34032 is #176, CVE-2026-28780 is #174, CVE-2026-33007 is #109)

    Post summary

    Four CVEs first discovered by Swival are reported as already fixed in Apache 2.4.67, underscoring the importance of the patch update.

    200301.2K
    17.4K followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-httpd24 モジュール更新情報 2.4.67-1 https://kusanagi.tokyo/releases/24495/ KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 httpd24 2.4.67-1 この更新には脆弱性(CVE-2026-34059, CVE-2026-34032, CVE-2026-33857, CVE-2026-33523, CVE-2026-33007, CVE-2026-33006, CVE-2026-...

    Post summary

    The release note announces a patch update for kusanagi-httpd24 that addresses several CVEs without providing technical details or exploitation information.

    0101066
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-httpd24 モジュール更新情報 2.4.67-1.el9 https://kusanagi.tokyo/releases/24489/ KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 httpd24 2.4.67-1.el9 この更新には脆弱性(CVE-2026-34059, CVE-2026-34032, CVE-2026-33857, CVE-2026-33523, CVE-2026-33007, CVE-2026-33006, C...

    Post summary

    Kusanagi httpd24 receives an updated module (2.4.67-1.el9) that patches multiple CVEs, as announced at the provided link.

    0101062
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-httpd24 Module Update 2.4.67-1 https://kusanagi.tokyo/en/releases/24496/ KUSANAGI 9 modules have been updated. The updated modules are as follows: httpd24 2.4.67-1 This update includes support for vulnerability(CVE-2026-34059, CVE-2026-34032, CVE-2026-33857, CVE-2026-33523,...

    Post summary

    KUSANAGI released a new httpd24 module (2.4.67‑1) that addresses multiple CVEs, including CVE‑2026‑34059, CVE‑2026‑34032, CVE‑2026‑33857, among others.

    0000042
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-httpd24 Module Update 2.4.67-1.el9 https://kusanagi.tokyo/en/releases/24490/ KUSANAGI 9 modules have been updated. The updated modules are as follows: httpd24 2.4.67-1.el9 This update includes support for vulnerability(CVE-2026-34059, CVE-2026-34032, CVE-2026-33857,...

    Post summary

    KUSANAGI released an httpd24 module update (2.4.67-1.el9) that includes patches for CVE-2026-34059, CVE-2026-34032, CVE-2026-33857, among others.

    0000032
    200 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-33857 Out-of-bounds Read vulnerability in mod_proxy_ajp of Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade t… https://www.cve.org/CVERecord?id=CVE-2026-33857 ----- Traducción: CVE-2026-33857 Lec… http://infoflow.cloud`

    Post summary

    A newly disclosed CVE‑2026‑33857 involves an out‑of‑bounds read in Apache HTTP Server's mod_proxy_ajp, affecting versions up to 2.4.66, and users are advised to upgrade.

    0000032
    75 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-33857 Out-of-bounds Read vulnerability in mod_proxy_ajp of Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade t… https://www.cve.org/CVERecord?id=CVE-2026-33857

    Post summary

    The notice informs users of CVE‑2026‑33857, an out‑of‑bounds read in Apache HTTP Server’s mod_proxy_ajp, and urges them to upgrade to mitigate the issue.

    00000133
    57.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachehttp_server---

Explore more