Apache Vulnerabilities
The Apache Software Foundation hosts open-source projects such as Log4j, Struts, Tomcat, ActiveMQ, OFBiz and the Apache HTTP Server. The database tracks 43 Apache CVE records. CISA lists 41 of them as exploited in the wild, most recently on 2026-10-08. The most affected products are Struts, Tomcat, HTTP Server.
Recently Exploited Apache CVEs
Apache Struts Command Injection Vulnerability
Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans
Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
Apache OFBiz: Confused controller-view authorization logic (forced browsing)
Affected Products
23 products| Product | CVEs | KEV | Latest |
|---|---|---|---|
| Struts | 6 | 6 | 2026-10-08 |
| Tomcat | 6 | 6 | 2026-08-04 |
| HTTP Server | 4 | 4 | 2025-05-01 |
| ActiveMQ | 3 | 3 | 2026-04-16 |
| OFBiz | 3 | 3 | 2025-02-04 |
| Log4j2 | 2 | 2 | 2023-05-01 |
| Solr | 2 | 2 | 2021-12-10 |
| Struts 1 | 2 | 2 | 2022-02-10 |
| Airflow | 1 | 1 | 2022-01-18 |
| Airflow's Experimental API | 1 | 1 | 2022-01-18 |
| Apache | 1 | 1 | 2021-12-01 |
| Apache HTTP Server | 1 | - | 2026-05-04 |
| Apache OpenNLP :: Core :: ML :: LibSVM | 1 | - | 2026-07-06 |
| APISIX | 1 | 1 | 2022-08-25 |
| CouchDB | 1 | 1 | 2022-08-25 |
| Flink | 1 | 1 | 2024-05-23 |
| HugeGraph-Server | 1 | 1 | 2024-09-18 |
| Kylin | 1 | 1 | 2022-03-25 |
| RocketMQ | 1 | 1 | 2023-09-06 |
| Shiro | 1 | 1 | 2021-11-03 |
| Spark | 1 | 1 | 2023-03-07 |
| Struts 2 | 1 | 1 | 2022-01-21 |
| Superset | 1 | 1 | 2024-01-08 |
All Apache CVEs
43 records| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2016-3081 | Apache Struts Command Injection Vulnerability | - | 8.1 | 93.4% | KEV | 2016-04-26 |
| CVE-2026-34486 | Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor | Apache Software Foundation | 7.5 | 6.6% | KEV | 2026-04-09 |
| CVE-2026-34197 | Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans | Apache Software Foundation | 8.8 | 15.5% | KEV | 2026-04-07 |
| CVE-2024-38475 | Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path. | Apache Software Foundation | 9.1 | 100.0% | KEV | 2024-07-01 |
| CVE-2025-24813 | Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT | Apache Software Foundation | 10.0 | 99.9% | KEV | 2025-03-10 |
| CVE-2024-45195 | Apache OFBiz: Confused controller-view authorization logic (forced browsing) | Apache Software Foundation | 9.8 | 100.0% | KEV | 2024-09-04 |
| CVE-2024-27348 | Apache HugeGraph-Server: Command execution in gremlin | Apache Software Foundation | 9.8 | 99.2% | KEV | 2024-04-22 |
| CVE-2024-38856 | Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code | Apache Software Foundation | 8.1 | 99.4% | KEV | 2024-08-05 |
| CVE-2024-32113 | Apache OFBiz: Path traversal leading to RCE | Apache Software Foundation | 9.1 | 99.9% | KEV | 2024-05-08 |
| CVE-2020-17519 | Apache Flink directory traversal attack: reading remote files through the REST API | Apache Software Foundation | 9.1 | 97.8% | KEV | 2021-01-05 |
| CVE-2023-27524 | Apache Superset: Session validation vulnerability when using provided default SECRET_KEY | Apache Software Foundation | 8.9 | 97.4% | KEV | 2023-04-24 |
| CVE-2023-46604 | Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack | Apache Software Foundation | 10.0 | 99.9% | KEV | 2023-10-27 |
| CVE-2023-33246 | Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function | Apache Software Foundation | 9.8 | 96.6% | KEV | 2023-05-24 |
| CVE-2016-8735 | Apache Tomcat Remote Code Execution Vulnerability | Apache Software Foundation | 9.8 | 90.3% | KEV | 2017-04-06 |
| CVE-2021-45046 | Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack | Apache Software Foundation | 9.0 | 100.0% | KEV | 2021-12-14 |
| CVE-2022-33891 | Apache Spark shell command injection vulnerability via Spark UI | Apache Software Foundation | 8.8 | 93.2% | KEV | 2022-07-18 |
| CVE-2022-24112 | apisix/batch-requests plugin allows overwriting the X-REAL-IP header | Apache Software Foundation | 9.8 | 96.1% | KEV | 2022-02-11 |
| CVE-2022-24706 | Remote Code Execution Vulnerability in Packaging | Apache Software Foundation | 9.8 | 92.5% | KEV | 2022-04-26 |
| CVE-2013-2251 | Apache Struts Improper Input Validation Vulnerability | - | 9.8 | 100.0% | KEV | 2013-07-18 |
| CVE-2017-12617 | Apache Tomcat Remote Code Execution Vulnerability | Apache Software Foundation | 8.1 | 100.0% | KEV | 2017-10-03 |
| CVE-2017-12615 | Apache Tomcat on Windows Remote Code Execution Vulnerability | Apache Software Foundation | 8.1 | 99.6% | KEV | 2017-09-19 |
| CVE-2020-1956 | Apache Kylin OS Command Injection Vulnerability | Apache | 8.8 | 97.3% | KEV | 2020-05-22 |
| CVE-2020-1938 | Apache Tomcat Improper Privilege Management Vulnerability | Apache | 9.8 | 99.3% | KEV | 2020-02-24 |
| CVE-2017-9791 | Apache Struts 1 Improper Input Validation Vulnerability | Apache Software Foundation | 9.8 | 98.9% | KEV | 2017-07-10 |
| CVE-2016-3088 | Apache ActiveMQ Improper Input Validation Vulnerability | - | 9.8 | 98.5% | KEV | 2016-06-01 |
| CVE-2012-0391 | Apache Struts 2 Improper Input Validation Vulnerability | - | 9.8 | 75.6% | KEV | 2012-01-08 |
| CVE-2006-1547 | Apache Struts 1 ActionForm Denial-of-Service Vulnerability | - | 7.5 | 54.6% | KEV | 2006-03-30 |
| CVE-2020-13927 | Apache Airflow's Experimental API Authentication Bypass | - | 9.8 | 99.8% | KEV | 2020-11-10 |
| CVE-2020-11978 | Apache Airflow Command Injection | Apache Software Foundation | 8.8 | 99.2% | KEV | 2020-07-16 |
| CVE-2021-44228 | Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints | Apache Software Foundation | 10.0 | 100.0% | KEV | 2021-12-10 |
| CVE-2019-0193 | Apache Solr DataImportHandler Code Injection Vulnerability | Apache | 7.2 | 83.5% | KEV | 2019-08-01 |
| CVE-2021-40438 | mod_proxy SSRF | Apache Software Foundation | 9.0 | 100.0% | KEV | 2021-09-16 |
| CVE-2017-5638 | Apache Struts Remote Code Execution Vulnerability | Apache Software Foundation | 9.8 | 100.0% | KEV | 2017-03-11 |
| CVE-2021-41773 | Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49 | Apache Software Foundation | 7.5 | 100.0% | KEV | 2021-10-05 |
| CVE-2018-11776 | Apache Struts Remote Code Execution Vulnerability | Apache Software Foundation | 8.1 | 100.0% | KEV | 2018-08-22 |
| CVE-2021-42013 | Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773) | Apache Software Foundation | 9.8 | 100.0% | KEV | 2021-10-07 |
| CVE-2017-9805 | Apache Struts Deserialization of Untrusted Data Vulnerability | Apache Software Foundation | 8.1 | 99.4% | KEV | 2017-09-15 |
| CVE-2019-17558 | Apache Solr VelocityResponseWriter Plug-In Remote Code Execution Vulnerability | - | 7.5 | 98.6% | KEV | 2019-12-30 |
| CVE-2020-17530 | Apache Struts Remote Code Execution Vulnerability | Apache Software Foundation | 9.8 | 95.9% | KEV | 2020-12-11 |
| CVE-2016-4437 | Apache Shiro Code Execution Vulnerability | - | 9.8 | 93.0% | KEV | 2016-06-07 |
| CVE-2019-0211 | Apache HTTP Server Privilege Escalation Vulnerability | Apache | 7.8 | 65.0% | KEV | 2019-04-08 |
| CVE-2026-23918 | Apache HTTP Server: http2: double free and possible RCE on early reset | Apache Software Foundation | 8.8 | 49.7% | 2026-05-04 | |
| CVE-2026-43825 | Apache OpenNLP :: Core :: ML :: LibSVM: Unsafe Java Deserialization in SvmDoccatModel | Apache Software Foundation | 7.3 | 13.9% | 2026-07-06 |
Frequently Asked Questions
How many Apache vulnerabilities are actively exploited?→
41 Apache CVEs are in the CISA Known Exploited Vulnerabilities catalog as of 2026-10-09. The latest was added on 2026-10-08.
Which Apache vulnerabilities are used in ransomware attacks?→
CISA marks 8 Apache KEV entries as known to be used in ransomware campaigns, including CVE-2023-46604, CVE-2021-45046, CVE-2017-12615, CVE-2021-44228, CVE-2021-40438.
Which Apache products have the most exploited vulnerabilities?→
- +Struts: 6 CVEs (6 in KEV)
- +Tomcat: 6 CVEs (6 in KEV)
- +HTTP Server: 4 CVEs (4 in KEV)
- +ActiveMQ: 3 CVEs (3 in KEV)
- +OFBiz: 3 CVEs (3 in KEV)
Where does Apache publish security advisories?→
Apache publishes security advisories at https://www.apache.org/security/. Check the vendor advisory for fixed versions and workarounds before applying updates.
Sources
CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Vendor and product names for exploited CVEs follow the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not affiliated with or endorsed by Apache, MITRE, CISA, or FIRST.