Junglewise

Vendor

Apache vulnerabilities

Updated . Rebuilt every hour.

Junglewise Threat Intelligence has tracked 558 vulnerabilities in Apache: 43 in the last 7 days and 289 in the last 90 days, 130 of them critical and 41 exploited in the wild. The most recent, CVE-2026-92573, was published on 25 September 2026. 34 technologies have a page of their own.

Last 7 days
43
Last 90 days
289
Critical, all time
130
Exploited in the wild
41

About Apache

Apache Software Foundation develops open-source software projects including web servers, middleware, and other applications.

Homepage

Apache technologies

Latest Apache vulnerabilities

Most severe Apache vulnerabilities

Exploited in the wild first, then by severity and CVSS score.

Vulnerabilities per week

The last 13 weeks, by the week each vulnerability was published.

Vulnerabilities published per week, UTC
Week ofBarVulnsCritical
29 Jun 2026
110
6 Jul 2026
459
13 Jul 2026
50
20 Jul 2026
10
27 Jul 2026
466
3 Aug 2026
10
10 Aug 2026
267
17 Aug 2026
316
24 Aug 2026
247
31 Aug 2026
81
7 Sep 2026
167
14 Sep 2026
328
21 Sep 2026
437

How this is built

Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.

The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.

Use this data

The same data is at https://junglewise.ai/threats/vendors/apache.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.

Cite as: Junglewise Threat Intelligence, "Apache vulnerabilities", https://junglewise.ai/threats/vendors/apache, 26 September 2026.