Summary
| Parameter | Value |
|---|---|
| CVE ID | CVE-2026-28780 |
| Alert Source | GitHub Advisory - Critical Vulnerability |
| CVE Publication Year | 2026 |
| Date Published | 2026-05-06 |
| Vendor | Apache |
| Product | HTTP Server |
| CVSS Score | 9.8 (critical) |
| EPSS Score | 0.0% (percentile: 5%) |
| CISA KEV | No |
| Ransomware | Not confirmed |
Vulnerability Description
Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to write 4 attacker controlled bytes after the end of a heap based buffer.
This issue affects Apache HTTP Server: through 2.4.66.
Users are recommended to upgrade to version 2.4.67, which fixes the issue.
Required Actions
Apply vendor patches or mitigations as soon as available.
Who Is Affected?
This vulnerability affects HTTP Server by Apache. Check if your organization uses this software and requires updates.
Sources
Need help securing your systems? nFlo team offers vulnerability management and 24/7 SOC services. Contact us.
