CVE-2026-93546

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory's property database via PROPPATCH requests declaring many XML namespaces.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-190

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 1 mentions (2026-10-01); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-10-01: 1Mentions · 2026-10-02: 110-0110-02
Referenced assets2 URLs
Full discourse2 posts
  • Kazuki Omo@omokazuki

    Apache HTTP Serverの脆弱性(Moderate: CVE-2026-42528, CVE-2026-57941, CVE-2026-59685, CVE-2026-63292, CVE-2026-93546, Low: 複数)と2.4.69リリース #sios_tech #security #vulnerability #セキュリティ #脆弱性 #apache https://security.sios.jp/vulnerability/apache-security-vulnerability-20261002/

    00011105
    374 followersView on X
  • Rıdvan Yağlı@ridvanyagli

    🔴 Apache HTTP Server 2.4.69 yayınlandı. Güncelleme, 2.4.68 ve öncesini etkileyen 20 güvenlik açığını gideriyor. Öne çıkan önemli açıklar: • CVE-2026-63292: mod_vhost_alias — DoS ve koşullu kod çalıştırma • CVE-2026-42356: CGI handler — sınırlı kod çalıştırma • CVE-2026-57941: mod_http2 — UAF / bellek yazma • CVE-2026-93546: mod_dav_fs — crash ve veritabanı bozulması Açıkların çoğu Moderate/Low seviyede ve sömürülebilirlik yapılandırmaya bağlı. Apache 2.4.69'a güncellemeyi düşünün. https://www.apachelounge.com/changelog-2.4.html

    00010152
    2.4K followersView on X

Explore more