CVE-2026-34032Patch(apache / http_server)

MEDIUMCVSS 5.3 · MEDIUM

Exploitation ongoing with high activity in latest observed window (4 mentions)

Immediate actions

  • Patch apache http_server systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125CWE-170

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • http_server

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 10 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 8 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked at 4 mentions on most recent observed day (2026-05-11)
  • 10 total mentions across 4 days

Affected systems

Vendors
Products
http_server

Deep dive

Activity timeline10 mentions / 4d
01234Mentions · 2026-05-04: 3Mentions · 2026-05-05: 2Mentions · 2026-05-07: 1Mentions · 2026-05-11: 4Active Exploitation · 2026-05-05: 1Patch / Workaround · 2026-05-04: 2Patch / Workaround · 2026-05-05: 1Patch / Workaround · 2026-05-07: 1Patch / Workaround · 2026-05-11: 4Technical Details · 2026-05-04: 305-0405-0505-0705-11
Signal classification3 categories
Patch
770.0%
Disclosure
220.0%
Active Exploitation
110.0%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-05-043
Disclosure2Patch1
2026-05-052
Active Exploitation1Patch1
2026-05-071
Patch1
2026-05-114
Patch4
Full discourse10 posts
  • Frank@jedisct1
    Patch

    At least 4 vulnerabilities fixed in Apache 2.4.67 were already independently found by Swival https://github.com/Swival/security-audits/tree/main/apache-httpd#apache-httpd-audit-findings (CVE-2026-33857 is #175, CVE-2026-34032 is #176, CVE-2026-28780 is #174, CVE-2026-33007 is #109)

    Post summary

    The post reports that four CVEs, identified by Swival and fixed in Apache 2.4.67, are remedied by the newer release, but it offers no proof‑of‑concept, exploit details, or evidence of active exploitation.

    200301.2K
    17.4K followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-httpd24 モジュール更新情報 2.4.67-1 https://kusanagi.tokyo/releases/24495/ KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 httpd24 2.4.67-1 この更新には脆弱性(CVE-2026-34059, CVE-2026-34032, CVE-2026-33857, CVE-2026-33523, CVE-2026-33007, CVE-2026-33006, CVE-2026-...

    Post summary

    The release notes announce an update to the Kusanaagi httpd24 module that patches several CVEs; no PoC, exploit, or active exploitation details are provided.

    0101066
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-httpd24 モジュール更新情報 2.4.67-1.el9 https://kusanagi.tokyo/releases/24489/ KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 httpd24 2.4.67-1.el9 この更新には脆弱性(CVE-2026-34059, CVE-2026-34032, CVE-2026-33857, CVE-2026-33523, CVE-2026-33007, CVE-2026-33006, C...

    Post summary

    The Kusanagi module update provides patches for several listed CVEs in httpd 2.4.67, with no poC, exploit, or active exploitation evidence present.

    0101062
    200 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-34032 Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to u… https://www.cve.org/CVERecord?id=CVE-2026-34032

    Post summary

    The statement highlights a vulnerability in Apache HTTP Server and recommends a patch update, without providing PoC, exploit details, or evidence of active exploitation.

    00010140
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-34032 Out-of-Bounds Read Vulnerability in Apache HTTP Server Through 2.4.66 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-34032

    Post summary

    The text announces CVE‑2026‑34032, an out‑of‑bounds read vulnerability in Apache HTTP Server up to 2.4.66, with no evidence of PoC, exploit code, patch, or active exploitation.

    0001063
    4.0K followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-httpd24 Module Update 2.4.67-1 https://kusanagi.tokyo/en/releases/24496/ KUSANAGI 9 modules have been updated. The updated modules are as follows: httpd24 2.4.67-1 This update includes support for vulnerability(CVE-2026-34059, CVE-2026-34032, CVE-2026-33857, CVE-2026-33523,...

    Post summary

    This release provides patched modules for multiple CVEs, indicating a standard vulnerability fix rather than exploitation or PoC details.

    0000042
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-httpd24 Module Update 2.4.67-1.el9 https://kusanagi.tokyo/en/releases/24490/ KUSANAGI 9 modules have been updated. The updated modules are as follows: httpd24 2.4.67-1.el9 This update includes support for vulnerability(CVE-2026-34059, CVE-2026-34032, CVE-2026-33857,...

    Post summary

    Kusanagi HTTPD modules were updated to version 2.4.67-1.el9, applying patches for CVE-2026-34059, CVE-2026-34032, CVE-2026-33857, and related vulnerabilities.

    0000032
    200 followersView on X
  • WindowsForum@windowsforum
    Patch

    🪟 CVE-2026-34032 is Apache mod_proxy_ajp… but MSRC “broken page” vibes are louder than the actual bug. Still: if you proxy AJP on Windows, patch to 2.4.67 now. #Windows #Security https://windowsforum.com/threads/cve-2026-34032-patch-apache-mod_proxy_ajp-on-windows-upgrade-to-2-4-67.416795/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #WindowsPatching #ApacheHttpServer #ModProxyAjp #AjpProxy https://t.co/JcZ4lauRBk

    Post summary

    The thread warns Windows users about CVE-2026-34032 in Apache mod_proxy_ajp and recommends upgrading to version 2.4.67 as a patch.

    0000072
    1.1K followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    Some increased actor activities are shown targeting Apache HTTP Server (CVE-2026-34032) https://vuldb.com/vuln/360959/cti

    Post summary

    The post reports increased attacker activity targeting the CVE‑2026‑34032 vulnerability in Apache HTTP Server, suggesting potential in‑the‑wild exploitation, but no technical details or patch information are provided.

    0000059
    2.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-34032 Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to u… https://www.cve.org/CVERecord?id=CVE-2026-34032 ----- Traducción: CVE-2026-34032 Ter… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑34032 as an improper null termination/out‑of‑bounds read in Apache HTTP Server, recommends an update, and points to the CVE record for details.

    0000030
    75 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachehttp_server---

Explore more