Apache has patched a high-severity vulnerability (CVE-2026-23918) in HTTP Server ≤2.4.66. The issue is a double-free memory corruption bug in HTTP/2 handling that can potentially lead to remote code execution under certain conditions.
Rated CVSS 8.8, and part of a batch of fixes in 2.4.67. Given Apache’s footprint, patching seems important, especially for deployments with HTTP/2 enabled.
More Details: https://thecybersecguru.com/news/apache-rce-vulnerability-cve-2026-23918/
[link] [comments]