{"schema_version":1,"title":"Apache vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 576 vulnerabilities in Apache: 60 in the last 7 days and 300 in the last 90 days, 133 of them critical and 41 exploited in the wild. The most recent, CVE-2026-86507, was published on 28 September 2026. 38 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/apache","json_url":"https://junglewise.ai/threats/vendors/apache.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/apache","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":203,"all_time":576,"critical":133,"exploited":41,"last_7_days":60,"last_30_days":117,"last_90_days":300,"last_365_days":485},"latest":[{"cve":"CVE-2026-86507","cvss":6.1,"slug":"cve-2026-86507-improper-neutralization-of-input-in-apache-roller-6-1-5-allows-an","title":"Apache Roller stored XSS in comment author URL","severity":"medium","exploited":false,"published_at":"2026-09-28T09:17:07.52+00:00","url":"https://junglewise.ai/threats/cve-2026-86507-improper-neutralization-of-input-in-apache-roller-6-1-5-allows-an"},{"cve":"CVE-2026-91206","cvss":6.1,"slug":"cve-2026-91206-improper-neutralization-of-input-during-web-page-generation-cross","title":"Apache Roller cross-site scripting in LDAP comment form","severity":"medium","exploited":false,"published_at":"2026-09-28T08:16:43.013+00:00","url":"https://junglewise.ai/threats/cve-2026-91206-improper-neutralization-of-input-during-web-page-generation-cross"},{"cve":"CVE-2026-91204","cvss":6.1,"slug":"cve-2026-91204-improper-neutralization-of-input-during-web-page-generation-cross","title":"Apache Roller cross-site scripting in HTML comments","severity":"medium","exploited":false,"published_at":"2026-09-28T08:16:42.887+00:00","url":"https://junglewise.ai/threats/cve-2026-91204-improper-neutralization-of-input-during-web-page-generation-cross"},{"cve":"CVE-2026-82546","cvss":6.1,"slug":"cve-2026-82546-improper-neutralization-of-input-during-web-page-generation-cross","title":"Apache Roller stored cross-site scripting in Trackback comments","severity":"medium","exploited":false,"published_at":"2026-09-28T08:16:42.763+00:00","url":"https://junglewise.ai/threats/cve-2026-82546-improper-neutralization-of-input-during-web-page-generation-cross"},{"cve":"CVE-2026-82387","cvss":5.4,"slug":"cve-2026-82387-improper-neutralization-of-input-during-web-page-generation-cross","title":"Apache Roller cross-site scripting in media upload","severity":"medium","exploited":false,"published_at":"2026-09-28T08:16:42.647+00:00","url":"https://junglewise.ai/threats/cve-2026-82387-improper-neutralization-of-input-during-web-page-generation-cross"},{"cve":"CVE-2026-82386","cvss":7.7,"slug":"cve-2026-82386-improper-restriction-of-xml-external-entity-reference-in-apache","title":"Apache Roller XML external entity injection in bookmark import","severity":"high","exploited":false,"published_at":"2026-09-28T08:16:42.527+00:00","url":"https://junglewise.ai/threats/cve-2026-82386-improper-restriction-of-xml-external-entity-reference-in-apache"},{"cve":"CVE-2026-82385","cvss":6.5,"slug":"cve-2026-82385-exposure-of-sensitive-information-to-an-unauthorized-actor-in","title":"Apache Roller information disclosure in Velocity templates","severity":"medium","exploited":false,"published_at":"2026-09-28T08:16:42.403+00:00","url":"https://junglewise.ai/threats/cve-2026-82385-exposure-of-sensitive-information-to-an-unauthorized-actor-in"},{"cve":"CVE-2026-82384","cvss":9.8,"slug":"cve-2026-82384-deserialization-of-untrusted-data-in-apache-roller-6-1-5-allows","title":"Apache Roller XML-RPC deserialization of untrusted data","severity":"critical","exploited":false,"published_at":"2026-09-28T08:16:42.273+00:00","url":"https://junglewise.ai/threats/cve-2026-82384-deserialization-of-untrusted-data-in-apache-roller-6-1-5-allows"},{"cve":"CVE-2026-82383","cvss":8.2,"slug":"cve-2026-82383-missing-authentication-for-critical-function-in-apache-roller-6-1","title":"Apache Roller missing authentication in setup action","severity":"high","exploited":false,"published_at":"2026-09-28T08:16:42.153+00:00","url":"https://junglewise.ai/threats/cve-2026-82383-missing-authentication-for-critical-function-in-apache-roller-6-1"},{"cve":"CVE-2026-82382","cvss":6.1,"slug":"cve-2026-82382-improper-neutralization-of-input-during-web-page-generation-cross","title":"Apache Roller cross-site scripting in frontpage theme","severity":"medium","exploited":false,"published_at":"2026-09-28T08:16:42.037+00:00","url":"https://junglewise.ai/threats/cve-2026-82382-improper-neutralization-of-input-during-web-page-generation-cross"},{"cve":"CVE-2026-82381","cvss":5.4,"slug":"cve-2026-82381-improper-neutralization-of-input-during-web-page-generation-cross","title":"Apache Roller stored cross-site scripting in authoring UI","severity":"medium","exploited":false,"published_at":"2026-09-28T08:16:41.913+00:00","url":"https://junglewise.ai/threats/cve-2026-82381-improper-neutralization-of-input-during-web-page-generation-cross"},{"cve":"CVE-2026-82380","cvss":8.1,"slug":"cve-2026-82380-cross-site-request-forgery-csrf-in-apache-roller-6-1-5-allows-a","title":"Apache Roller CSRF in state-changing actions","severity":"high","exploited":false,"published_at":"2026-09-28T08:16:41.787+00:00","url":"https://junglewise.ai/threats/cve-2026-82380-cross-site-request-forgery-csrf-in-apache-roller-6-1-5-allows-a"},{"cve":"CVE-2026-82379","cvss":7.7,"slug":"cve-2026-82379-authentication-bypass-by-capture-replay-in-apache-roller-6-1-5","title":"Apache Roller authentication bypass in AtomPub WSSE","severity":"high","exploited":false,"published_at":"2026-09-28T08:16:41.663+00:00","url":"https://junglewise.ai/threats/cve-2026-82379-authentication-bypass-by-capture-replay-in-apache-roller-6-1-5"},{"cve":"CVE-2026-82378","cvss":9,"slug":"cve-2026-82378-incorrect-authorization-in-the-oauth-1-0a-authorization-endpoint","title":"Apache Roller incorrect authorization in OAuth 1.0a endpoint","severity":"critical","exploited":false,"published_at":"2026-09-28T08:16:41.54+00:00","url":"https://junglewise.ai/threats/cve-2026-82378-incorrect-authorization-in-the-oauth-1-0a-authorization-endpoint"},{"cve":"CVE-2026-82377","cvss":9.9,"slug":"cve-2026-82377-missing-authorization-in-apache-roller-6-1-5-allows-an","title":"Apache Roller missing authorization in XML-RPC APIs","severity":"critical","exploited":false,"published_at":"2026-09-28T08:16:41.417+00:00","url":"https://junglewise.ai/threats/cve-2026-82377-missing-authorization-in-apache-roller-6-1-5-allows-an"},{"cve":"CVE-2026-82376","cvss":7.7,"slug":"cve-2026-82376-improper-restriction-of-xml-external-entity-reference-in-apache","title":"Apache Roller XML External Entity Injection","severity":"high","exploited":false,"published_at":"2026-09-28T08:16:41.293+00:00","url":"https://junglewise.ai/threats/cve-2026-82376-improper-restriction-of-xml-external-entity-reference-in-apache"},{"cve":"CVE-2026-82375","cvss":7.4,"slug":"cve-2026-82375-server-side-request-forgery-ssrf-in-apache-roller-6-1-5-allows-an","title":"Apache Roller Server-Side Request Forgery in trackback and enclosure handling","severity":"high","exploited":false,"published_at":"2026-09-28T08:16:41.17+00:00","url":"https://junglewise.ai/threats/cve-2026-82375-server-side-request-forgery-ssrf-in-apache-roller-6-1-5-allows-an"},{"cve":"CVE-2026-82348","cvss":7.7,"slug":"cve-2026-82348-authorization-bypass-through-user-controlled-key-in-apache-roller","title":"Apache Roller authorization bypass through unscoped resource lookups","severity":"high","exploited":false,"published_at":"2026-09-28T08:16:40.99+00:00","url":"https://junglewise.ai/threats/cve-2026-82348-authorization-bypass-through-user-controlled-key-in-apache-roller"},{"cve":"CVE-2026-92573","cvss":6.5,"epss":0.0016,"slug":"cve-2026-92573-improper-handling-of-compressed-data-in-the-shared-gzip","title":"Apache Qpid Broker-J GZIP decompression denial of service","severity":"medium","exploited":false,"published_at":"2026-09-25T09:17:06.837+00:00","url":"https://junglewise.ai/threats/cve-2026-92573-improper-handling-of-compressed-data-in-the-shared-gzip"},{"cve":"CVE-2026-92564","epss":0.0019,"slug":"cve-2026-92564-a-pre-authentication-attacker-could-leverage-type-nesting-to","title":"Apache Qpid Broker-J stack overflow in type parsing","severity":"info","exploited":false,"published_at":"2026-09-25T09:17:06.717+00:00","url":"https://junglewise.ai/threats/cve-2026-92564-a-pre-authentication-attacker-could-leverage-type-nesting-to"},{"cve":"CVE-2026-92560","cvss":7.5,"epss":0.0019,"slug":"cve-2026-92560-a-pre-authentication-attacker-could-leverage-type-size-count","title":"Apache Qpid Broker-J memory exhaustion denial of service","severity":"high","exploited":false,"published_at":"2026-09-25T09:17:06.587+00:00","url":"https://junglewise.ai/threats/cve-2026-92560-a-pre-authentication-attacker-could-leverage-type-size-count"},{"cve":"CVE-2026-92550","cvss":7.5,"epss":0.0019,"slug":"cve-2026-92550-a-pre-authentication-attacker-could-leverage-type-size-count","title":"Apache Qpid Broker-J denial of service via type allocation","severity":"high","exploited":false,"published_at":"2026-09-25T09:17:06.447+00:00","url":"https://junglewise.ai/threats/cve-2026-92550-a-pre-authentication-attacker-could-leverage-type-size-count"},{"cve":"CVE-2026-92609","cvss":9.8,"epss":0.002,"slug":"cve-2026-92609-session-fixation-in-http-management-authentication-allows-remote","title":"Apache Qpid Broker-J session fixation in HTTP management authentication","severity":"critical","exploited":false,"published_at":"2026-09-25T08:16:41.203+00:00","url":"https://junglewise.ai/threats/cve-2026-92609-session-fixation-in-http-management-authentication-allows-remote"},{"cve":"CVE-2026-92608","cvss":7.5,"epss":0.0016,"slug":"cve-2026-92608-improper-handling-of-property-encoding-exceptions-in-amqp-1-0-to","title":"Apache Qpid Broker-J improper AMQP message property encoding exception handling","severity":"high","exploited":false,"published_at":"2026-09-25T08:16:41.083+00:00","url":"https://junglewise.ai/threats/cve-2026-92608-improper-handling-of-property-encoding-exceptions-in-amqp-1-0-to"},{"cve":"CVE-2026-97636","cvss":6.5,"epss":0.0021,"slug":"cve-2026-97636-apache-airflow-hashicorp-provider-the-hashicorp-vault-secrets","title":"Apache Airflow HashiCorp provider secrets backend team-scope bypass","severity":"medium","exploited":false,"published_at":"2026-09-24T22:17:02.66+00:00","url":"https://junglewise.ai/threats/cve-2026-97636-apache-airflow-hashicorp-provider-the-hashicorp-vault-secrets"}],"vendor":{"hub":true,"name":"Apache","slug":"apache","homepage":"https://apache.org","description":"Apache Software Foundation develops open-source software projects including web servers, middleware, and other applications.","url":"https://junglewise.ai/threats/vendors/apache"},"weekly":[{"week":"2026-07-06","critical":9,"exploited":1,"vulnerabilities":45},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":5},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-27","critical":6,"exploited":0,"vulnerabilities":46},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-10","critical":7,"exploited":0,"vulnerabilities":26},{"week":"2026-08-17","critical":6,"exploited":0,"vulnerabilities":31},{"week":"2026-08-24","critical":7,"exploited":0,"vulnerabilities":24},{"week":"2026-08-31","critical":1,"exploited":0,"vulnerabilities":8},{"week":"2026-09-07","critical":7,"exploited":0,"vulnerabilities":16},{"week":"2026-09-14","critical":8,"exploited":0,"vulnerabilities":32},{"week":"2026-09-21","critical":7,"exploited":0,"vulnerabilities":43},{"week":"2026-09-28","critical":3,"exploited":0,"vulnerabilities":18}],"most_severe":[{"cve":"CVE-2012-0391","cvss":9.8,"epss":0.756,"slug":"cve-2012-0391-apache-struts-2-improper-input-validation-vulnerability","title":"Apache Struts Remote Java Code Execution","severity":"critical","exploited":true,"published_at":"2022-05-04T00:29:43+00:00","url":"https://junglewise.ai/threats/cve-2012-0391-apache-struts-2-improper-input-validation-vulnerability"},{"cve":"CVE-2024-45195","cvss":9.8,"slug":"cve-2024-45195-apache-ofbiz-forced-browsing-vulnerability","title":"Apache OFBiz Forced Browsing Vulnerability","severity":"critical","exploited":true,"published_at":"2025-02-04T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2024-45195-apache-ofbiz-forced-browsing-vulnerability"},{"cve":"CVE-2024-38856","cvss":9.8,"slug":"cve-2024-38856-apache-ofbiz-incorrect-authorization-vulnerability","title":"Apache OFBiz Incorrect Authorization Vulnerability","severity":"critical","exploited":true,"published_at":"2024-08-27T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2024-38856-apache-ofbiz-incorrect-authorization-vulnerability"},{"cve":"CVE-2024-32113","cvss":9.8,"slug":"cve-2024-32113-apache-ofbiz-path-traversal-vulnerability","title":"Apache OFBiz Path Traversal Vulnerability","severity":"critical","exploited":true,"published_at":"2024-08-07T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2024-32113-apache-ofbiz-path-traversal-vulnerability"},{"cve":"CVE-2022-24112","cvss":9.8,"slug":"cve-2022-24112-apache-apisix-authentication-bypass-vulnerability","title":"Apache APISIX Authentication Bypass Vulnerability","severity":"critical","exploited":true,"published_at":"2022-08-25T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2022-24112-apache-apisix-authentication-bypass-vulnerability"},{"cve":"CVE-2022-24706","cvss":9.8,"slug":"cve-2022-24706-apache-couchdb-insecure-default-initialization-of-resource","title":"Apache CouchDB Insecure Default Initialization of Resource Vulnerability","severity":"critical","exploited":true,"published_at":"2022-08-25T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2022-24706-apache-couchdb-insecure-default-initialization-of-resource"},{"cve":"CVE-2021-42013","cvss":9.8,"slug":"cve-2021-42013-apache-http-server-path-traversal-vulnerability","title":"Apache HTTP Server Path Traversal Vulnerability","severity":"critical","exploited":true,"published_at":"2021-11-03T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2021-42013-apache-http-server-path-traversal-vulnerability"},{"cve":"CVE-2021-41773","cvss":9.8,"slug":"cve-2021-41773-apache-http-server-path-traversal-vulnerability","title":"Apache HTTP Server Path Traversal Vulnerability","severity":"critical","exploited":true,"published_at":"2021-11-03T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2021-41773-apache-http-server-path-traversal-vulnerability"},{"cve":"CVE-2024-38475","cvss":9.1,"slug":"cve-2024-38475-apache-http-server-improper-escaping-of-output-vulnerability","title":"Apache HTTP Server Improper Escaping of Output Vulnerability","severity":"critical","exploited":true,"published_at":"2025-05-01T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2024-38475-apache-http-server-improper-escaping-of-output-vulnerability"},{"cve":"CVE-2021-40438","cvss":9,"slug":"cve-2021-40438-apache-http-server-side-request-forgery-ssrf","title":"Apache HTTP Server-Side Request Forgery (SSRF)","severity":"critical","exploited":true,"published_at":"2021-12-01T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2021-40438-apache-http-server-side-request-forgery-ssrf"}],"generated_at":"2026-09-28T09:56:32.590595+00:00","technologies":[{"name":"Apache Tomcat","slug":"tomcat","vulnerabilities":78,"url":"https://junglewise.ai/threats/technologies/tomcat"},{"name":"Apache Airflow","slug":"airflow","vulnerabilities":63,"url":"https://junglewise.ai/threats/technologies/airflow"},{"name":"Apache Camel","slug":"camel","vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/camel"},{"name":"Apache Traffic Server","slug":"traffic-server","vulnerabilities":39,"url":"https://junglewise.ai/threats/technologies/traffic-server"},{"name":"Apache HTTP Server","slug":"http-server","vulnerabilities":32,"url":"https://junglewise.ai/threats/technologies/http-server"},{"name":"Apache CloudStack","slug":"cloudstack","vulnerabilities":25,"url":"https://junglewise.ai/threats/technologies/cloudstack"},{"name":"Apache Ofbiz","slug":"ofbiz","vulnerabilities":22,"url":"https://junglewise.ai/threats/technologies/ofbiz"},{"name":"Apache ActiveMQ","slug":"activemq","vulnerabilities":19,"url":"https://junglewise.ai/threats/technologies/activemq"},{"name":"Apache Storm","slug":"storm","vulnerabilities":17,"url":"https://junglewise.ai/threats/technologies/storm"},{"name":"Apache Apisix","slug":"apisix","vulnerabilities":16,"url":"https://junglewise.ai/threats/technologies/apisix"},{"name":"Apache Thrift","slug":"thrift","vulnerabilities":16,"url":"https://junglewise.ai/threats/technologies/thrift"},{"name":"Apache ActiveMQ Artemis","slug":"activemq-artemis","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/activemq-artemis"},{"name":"Apache Ranger","slug":"ranger","vulnerabilities":12,"url":"https://junglewise.ai/threats/technologies/ranger"},{"name":"Apache ActiveMQ Broker","slug":"activemq-broker","vulnerabilities":11,"url":"https://junglewise.ai/threats/technologies/activemq-broker"},{"name":"Apache Artemis","slug":"artemis","vulnerabilities":10,"url":"https://junglewise.ai/threats/technologies/artemis"},{"name":"Apache Inlong","slug":"inlong","vulnerabilities":10,"url":"https://junglewise.ai/threats/technologies/inlong"},{"name":"Apache Superset","slug":"superset","vulnerabilities":10,"url":"https://junglewise.ai/threats/technologies/superset"},{"name":"Apache Allura","slug":"allura","vulnerabilities":8,"url":"https://junglewise.ai/threats/technologies/allura"},{"name":"Apache Shiro","slug":"shiro","vulnerabilities":8,"url":"https://junglewise.ai/threats/technologies/shiro"},{"name":"Apache DolphinScheduler","slug":"apache-dolphinscheduler-1","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/apache-dolphinscheduler-1"},{"name":"Apache Struts","slug":"struts","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/struts"},{"name":"Apache Tomcat-Embed-Core","slug":"tomcat-embed-core","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/tomcat-embed-core"},{"name":"Apache Zookeeper","slug":"zookeeper","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/zookeeper"},{"name":"Apache Qpid Broker-J","slug":"qpid-broker-j","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/qpid-broker-j"},{"name":"Apache Spark","slug":"spark","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/spark"},{"name":"Apache-Airflow-Providers-Fab","slug":"apache-airflow-providers-fab","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/apache-airflow-providers-fab"},{"name":"Apache Neethi","slug":"apache-neethi","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/apache-neethi"},{"name":"Apache Opennlp","slug":"opennlp","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/opennlp"},{"name":"Apache Sling XSS","slug":"sling-xss","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/sling-xss"},{"name":"Apache Struts 2","slug":"struts-2","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/struts-2"},{"name":"Apache Polaris","slug":"polaris","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/polaris"},{"name":"Apache Solr","slug":"solr","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/solr"},{"name":"Apache Camel JMS","slug":"camel-jms","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/camel-jms"},{"name":"Apache Camel SJMS","slug":"camel-sjms","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/camel-sjms"},{"name":"Apache Log4j","slug":"log4j","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/log4j"},{"name":"Apache Log4j2","slug":"log4j2","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/log4j2"},{"name":"Apache Nutch","slug":"nutch","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/nutch"},{"name":"Apache Tomcat Coyote","slug":"tomcat-coyote","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/tomcat-coyote"}]}