CVE-2026-34059Patch(apache / http_server)

MEDIUMCVSS 7.5 · HIGH

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Patch apache http_server systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Buffer Over-read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-126

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • http_server

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 10 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 8 signals
  • Technical details provided in 7 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 5 mentions (2026-05-04); latest day: 1
  • 10 total mentions across 3 days

Affected systems

Vendors
Products
http_server

Deep dive

Activity timeline10 mentions / 3d
01345Mentions · 2026-05-04: 5Mentions · 2026-05-11: 4Mentions · 2026-05-24: 1Active Exploitation · 2026-05-04: 1Patch / Workaround · 2026-05-04: 3Patch / Workaround · 2026-05-11: 4Patch / Workaround · 2026-05-24: 1Technical Details · 2026-05-04: 4Technical Details · 2026-05-11: 2Technical Details · 2026-05-24: 105-0405-1105-24
Signal classification3 categories
Patch
770.0%
Disclosure
220.0%
Active Exploitation
110.0%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-05-045
Active Exploitation1Disclosure1Patch3
2026-05-114
Disclosure1Patch3
2026-05-241
Patch1
Full discourse10 posts
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-httpd24 モジュール更新情報 2.4.67-1 https://kusanagi.tokyo/releases/24495/ KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 httpd24 2.4.67-1 この更新には脆弱性(CVE-2026-34059, CVE-2026-34032, CVE-2026-33857, CVE-2026-33523, CVE-2026-33007, CVE-2026-33006, CVE-2026-...

    Post summary

    The update for KUSANAGI 9 modules, including httpd24 2.4.67-1, fixes several CVEs listed in the release notes.

    0101066
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-httpd24 モジュール更新情報 2.4.67-1.el9 https://kusanagi.tokyo/releases/24489/ KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 httpd24 2.4.67-1.el9 この更新には脆弱性(CVE-2026-34059, CVE-2026-34032, CVE-2026-33857, CVE-2026-33523, CVE-2026-33007, CVE-2026-33006, C...

    Post summary

    The release updates httpd24 to 2.4.67‑1.el9, patching multiple CVEs to mitigate known vulnerabilities.

    0101062
    200 followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    Our CTI team identified a lot of activities targeting Apache HTTP Server (CVE-2026-34059) https://vuldb.com/vuln/360955/cti

    Post summary

    CTI analysts report numerous observed attacks targeting the recently disclosed Apache HTTP Server vulnerability CVE‑2026‑34059.

    0001063
    2.1K followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 Apache HTTP Server | CVE-2026-34059 Buffer over-read vulnerability that may expose sensitive memory data. If you’re running Apache: • Upgrade to a patched version • Limit exposure • Monitor for abnormal requests🔗 https://github.com/advisories/GHSA-m35f-pf48-r38q

    Post summary

    The advisory alerts to an Apache HTTP Server buffer‑over‑read vulnerability (CVE‑2026‑34059) and urges users to upgrade to the patched version while limiting exposure.

    0001096
    122 followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH severity CVE-2026-34059 (CVSS 7.5): Buffer Over-read in Apache HTTP Server through v2.4.66. Network-exploitable, no auth required. Upgrade to 2.4.67 immediately. #CVE #Vulnerability #PatchNow #ThreatIntel #DFIR https://t.co/TZlq3Vk1w5

    Post summary

    The tweet announces a high‑severity buffer over‑read (CVE‑2026‑34059) in Apache HTTP Server v2.4.66 and urges users to upgrade to v2.4.67 immediately.

    0000050
    30 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-httpd24 Module Update 2.4.67-1 https://kusanagi.tokyo/en/releases/24496/ KUSANAGI 9 modules have been updated. The updated modules are as follows: httpd24 2.4.67-1 This update includes support for vulnerability(CVE-2026-34059, CVE-2026-34032, CVE-2026-33857, CVE-2026-33523,...

    Post summary

    KUSANAGI has released updated modules that address several CVE-2026 vulnerabilities, representing a patch update without PoC, exploit code, or evidence of active exploitation.

    0000042
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Disclosure

    kusanagi-httpd24 Module Update 2.4.67-1.el9 https://kusanagi.tokyo/en/releases/24490/ KUSANAGI 9 modules have been updated. The updated modules are as follows: httpd24 2.4.67-1.el9 This update includes support for vulnerability(CVE-2026-34059, CVE-2026-34032, CVE-2026-33857,...

    Post summary

    The release notes announce module updates that patch several CVEs, but do not present exploit details or PoC information.

    0000032
    200 followersView on X
  • Infoflowcloud@infoflowcloud
    Patch

    🚨*CVE* CVE-2026-34059 Buffer Over-read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, whi… https://www.cve.org/CVERecord?id=CVE-2026-34059 ----- Traducción: CVE-2026-34059 vul… http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑34059, a buffer over‑read in Apache HTTP Server, recommends upgrading to 2.4.67, but provides no PoC, exploit, or evidence of active use.

    0000043
    75 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-34059 Buffer Over-read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, whi… https://www.cve.org/CVERecord?id=CVE-2026-34059

    Post summary

    Apache HTTP Server Buffer Over‑Read vulnerability CVE-2026-34059 is disclosed and mitigated by upgrading to version 2.4.67.

    00000148
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-34059 Buffer Over-read Vulnerability in Apache HTTP Server Through 2.4.66 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-34059

    Post summary

    The announcement identifies a buffer over-read vulnerability affecting Apache HTTP Server up to version 2.4.66, but provides no evidence of exploitation, PoC, or patching.

    0000065
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachehttp_server---

Explore more