Vendor
Apache vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 558 vulnerabilities in Apache: 43 in the last 7 days and 289 in the last 90 days, 130 of them critical and 41 exploited in the wild. The most recent, CVE-2026-92573, was published on 25 September 2026. 34 technologies have a page of their own.
- Last 7 days
- 43
- Last 90 days
- 289
- Critical, all time
- 130
- Exploited in the wild
- 41
About Apache
Apache Software Foundation develops open-source software projects including web servers, middleware, and other applications.
Apache technologies
- Apache Tomcat67
- Apache Airflow61
- Apache Camel40
- Apache Traffic Server39
- Apache HTTP Server31
- Apache CloudStack25
- Apache Ofbiz22
- Apache ActiveMQ19
- Apache Storm17
- Apache Apisix16
- Apache Thrift16
- Apache ActiveMQ Artemis15
- Apache Ranger12
- Apache ActiveMQ Broker11
- Apache Artemis10
- Apache Inlong10
- Apache Superset10
- Apache Allura8
- Apache Shiro8
- Apache Struts7
- Apache Tomcat-Embed-Core7
- Apache Zookeeper7
- Apache Spark6
- Apache-Airflow-Providers-Fab5
- Apache Opennlp5
- Apache Struts 25
- Apache Polaris4
- Apache Solr4
- Apache Camel JMS3
- Apache Camel SJMS3
- Apache Log4j3
- Apache Log4j23
- Apache Nutch3
- Apache Tomcat Coyote3
Latest Apache vulnerabilities
- CVE-2026-92573: Apache Qpid Broker-J GZIP decompression denial of servicemediumCVSS 6.5EPSS 0.2%
- CVE-2026-92564: Apache Qpid Broker-J stack overflow in type parsinginfoEPSS 0.2%
- CVE-2026-92560: Apache Qpid Broker-J memory exhaustion denial of servicehighCVSS 7.5EPSS 0.2%
- CVE-2026-92550: Apache Qpid Broker-J denial of service via type allocationhighCVSS 7.5EPSS 0.2%
- CVE-2026-92609: Apache Qpid Broker-J session fixation in HTTP management authenticationcriticalCVSS 9.8EPSS 0.2%
- CVE-2026-92608: Apache Qpid Broker-J improper AMQP message property encoding exception handlinghighCVSS 7.5EPSS 0.2%
- CVE-2026-97636: Apache Airflow HashiCorp provider secrets backend team-scope bypassmediumCVSS 6.5EPSS 0.2%
- CVE-2026-57590: Apache DolphinScheduler authorization bypass in Task Group APIshighCVSS 8.1EPSS 0.2%
- CVE-2026-86247: Apache Tomcat Native race condition in client certificate verificationhighCVSS 7.4EPSS 0.2%
- CVE-2026-86243: Apache Tomcat Native buffer over-read in TLS handshakehighCVSS 7.5EPSS 0.4%
- CVE-2026-87022: Apache Tomcat WebSocket message smuggling in per-message-deflatehighCVSS 7.5EPSS 0.4%
- CVE-2026-86350: Apache Tomcat HTTP/2 request smuggling via header mix-upcriticalCVSS 9.1EPSS 0.3%
- CVE-2026-86248: Apache Tomcat CLIENT_CERT authentication bypass when soft fail disabledcriticalCVSS 9.8EPSS 0.4%
- CVE-2026-79677: Apache Tomcat WebSocket denial of service due to lost async write timeouthighCVSS 7.5EPSS 0.3%
- CVE-2026-78437: Apache Tomcat incomplete cleanup denial of service in HTTP/2highCVSS 7.3EPSS 0.3%
- CVE-2026-78383: Apache Tomcat resource exhaustion in AJP connectorhighCVSS 7.5EPSS 0.4%
- CVE-2026-77791: Apache Tomcat denial of service in WebSocket close message handlinghighCVSS 7.5EPSS 0.5%
- CVE-2026-77762: Apache Tomcat HTTP/2 trailer field injection race conditionhighCVSS 8.1EPSS 0.4%
- CVE-2026-76183: Apache Tomcat authentication bypass in WebSocket endpointscriticalCVSS 9.8EPSS 0.4%
- CVE-2026-75973: Apache Tomcat improper authentication in Jakarta AuthenticationhighCVSS 7.3EPSS 0.2%
- CVE-2026-73581: Apache Tomcat certificate revocation check bypass in TLSmediumCVSS 6.5EPSS 0.1%
- CVE-2026-96443: Apache Doris JDBC driver URL validation bypassmediumCVSS 6.5EPSS 0.3%
- CVE-2026-94251: Apache Sling Security Bundle ContentDispositionFilter resource filtering bypassmediumCVSS 6.5EPSS 0.2%
- CVE-2026-94243: Apache Sling Security Bundle ReferrerFilter accepts weaker-than-origin evidencehighCVSS 7.3EPSS 0.1%
- CVE-2026-92001: Apache Sling XSS XML entity expansion vulnerabilitymediumCVSS 6.1EPSS 0.2%
Most severe Apache vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2012-0391: Apache Struts Remote Java Code Executioncriticalexploited in the wildCVSS 9.8EPSS 75.6%
- CVE-2024-45195: Apache OFBiz Forced Browsing Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2024-38856: Apache OFBiz Incorrect Authorization Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2024-32113: Apache OFBiz Path Traversal Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2022-24112: Apache APISIX Authentication Bypass Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2022-24706: Apache CouchDB Insecure Default Initialization of Resource Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2021-42013: Apache HTTP Server Path Traversal Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2021-41773: Apache HTTP Server Path Traversal Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2024-38475: Apache HTTP Server Improper Escaping of Output Vulnerabilitycriticalexploited in the wildCVSS 9.1
- CVE-2021-40438: Apache HTTP Server-Side Request Forgery (SSRF)criticalexploited in the wildCVSS 9
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 11 | 0 | |
| 6 Jul 2026 | 45 | 9 | |
| 13 Jul 2026 | 5 | 0 | |
| 20 Jul 2026 | 1 | 0 | |
| 27 Jul 2026 | 46 | 6 | |
| 3 Aug 2026 | 1 | 0 | |
| 10 Aug 2026 | 26 | 7 | |
| 17 Aug 2026 | 31 | 6 | |
| 24 Aug 2026 | 24 | 7 | |
| 31 Aug 2026 | 8 | 1 | |
| 7 Sep 2026 | 16 | 7 | |
| 14 Sep 2026 | 32 | 8 | |
| 21 Sep 2026 | 43 | 7 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/apache.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Apache vulnerabilities", https://junglewise.ai/threats/vendors/apache, 26 September 2026.