CVE-2026-40542Disclosure(apache / httpclient)

LOWCVSS 7.3 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch apache httpclient systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication verification. Users are recommended to upgrade to version 5.6.1, which fixes this issue.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-304CWE-325

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • httpclient

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 3 mentions (2026-04-23); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
httpclient

1 version affected across 1 product

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-04-23: 3Mentions · 2026-04-24: 1Mentions · 2026-04-28: 1PoC Mentioned / Linked · 2026-04-28: 1Patch / Workaround · 2026-04-23: 1Technical Details · 2026-04-23: 2Technical Details · 2026-04-28: 104-2304-2404-28
Signal classification3 categories
Disclosure
240.0%
General
240.0%
Patch
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-233
Disclosure1General1Patch1
2026-04-241
General1
2026-04-281
Disclosure1
Full discourse5 posts
  • Gray Hats@the_yellow_fall
    Patch

    Apache HttpClient 5.6 reveals a critical auth flaw (CVE-2026-40542) in SCRAM-SHA-256. Secure your Java microservices—upgrade to 5.6.1 immediately. #ApacheHttpClient #JavaSecurity #InfoSec #CyberSecurity #PatchNow #CVE202640542 #OpenSource https://securityonline.info/apache-httpclient-auth-bypass-cve-2026-40542-scram-sha-256/ https://t.co/iKwtwVEQ6W

    Post summary

    Apache HttpClient 5.6.1 patches a critical authentication flaw in SCRAM‑SHA‑256 (CVE-2026-40542); users are urged to upgrade immediately.

    02043372
    12.5K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-40542: Apache HttpClient 5.6 SCRAM-SHA-256 mutual authentication bypass https://www.openwall.com/lists/oss-security/2026/04/22/5 missing critical step in authentication

    Post summary

    The message announces CVE-2026-40542, a mutual authentication bypass in Apache HttpClient 5.6, and provides a link to additional discussion, but does not reveal patches, exploit code, or evidence of active exploitation.

    00041361
    4.7K followersView on X
  • takeo@cubdesign
    General

    CVE-2026-40542 とは? chatgpt, claude, gemini, mistral, grokに同じ質問をしたら。 mistral, claudeが、そんなのない!と何度も言っても認めない。答えを貼ると 見つかりました。失礼しました。 claudeってわざとやってる?

    Post summary

    The user asks about CVE‑2026‑40542 and notes AI responses, but no exploit, patch, technical detail, or active exploitation information is provided.

    10010135
    399 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidad en productos Apache ❗ CVE-2026-40542 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-productos-apache-9/ https://t.co/nMl1aPcmxW

    Post summary

    A brief Spanish-language post announces an Apache product vulnerability (CVE‑2026‑40542) and links to a source for further information.

    01000103
    6.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40542 Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual a… https://www.cve.org/CVERecord?id=CVE-2026-40542

    Post summary

    The tweet announces CVE‑2026‑40542, a critical authentication flaw in Apache HttpClient 5.6 that lets an attacker bypass required mutual authentication for SCRAM‑SHA‑256, with no mention of PoC, exploit, or fix.

    00000159
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachehttpclient5.6--

Explore more