Skip to main content

Recently Exploited Apache CVEs

Affected Products

23 products
ProductCVEsKEVLatest
Struts662026-10-08
Tomcat662026-08-04
HTTP Server442025-05-01
ActiveMQ332026-04-16
OFBiz332025-02-04
Log4j2222023-05-01
Solr222021-12-10
Struts 1222022-02-10
Airflow112022-01-18
Airflow's Experimental API112022-01-18
Apache112021-12-01
Apache HTTP Server1-2026-05-04
Apache OpenNLP :: Core :: ML :: LibSVM1-2026-07-06
APISIX112022-08-25
CouchDB112022-08-25
Flink112024-05-23
HugeGraph-Server112024-09-18
Kylin112022-03-25
RocketMQ112023-09-06
Shiro112021-11-03
Spark112023-03-07
Struts 2112022-01-21
Superset112024-01-08

Security Advisories

ASF Security Team (links to per-project security pages)
https://www.apache.org/security/

Weakness Types

All Apache CVEs

43 records
CVETitleVendorCVSSEPSSKEVPublished
CVE-2016-3081
Apache Struts Command Injection Vulnerability
-8.193.4%KEV2016-04-26
CVE-2026-34486
Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor
Apache Software Foundation7.56.6%KEV2026-04-09
CVE-2026-34197
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans
Apache Software Foundation8.815.5%KEV2026-04-07
CVE-2024-38475
Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.
Apache Software Foundation9.1100.0%KEV2024-07-01
CVE-2025-24813
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
Apache Software Foundation10.099.9%KEV2025-03-10
CVE-2024-45195
Apache OFBiz: Confused controller-view authorization logic (forced browsing)
Apache Software Foundation9.8100.0%KEV2024-09-04
CVE-2024-27348
Apache HugeGraph-Server: Command execution in gremlin
Apache Software Foundation9.899.2%KEV2024-04-22
CVE-2024-38856
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
Apache Software Foundation8.199.4%KEV2024-08-05
CVE-2024-32113
Apache OFBiz: Path traversal leading to RCE
Apache Software Foundation9.199.9%KEV2024-05-08
CVE-2020-17519
Apache Flink directory traversal attack: reading remote files through the REST API
Apache Software Foundation9.197.8%KEV2021-01-05
CVE-2023-27524
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
Apache Software Foundation8.997.4%KEV2023-04-24
CVE-2023-46604
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
Apache Software Foundation10.099.9%KEV2023-10-27
CVE-2023-33246
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
Apache Software Foundation9.896.6%KEV2023-05-24
CVE-2016-8735
Apache Tomcat Remote Code Execution Vulnerability
Apache Software Foundation9.890.3%KEV2017-04-06
CVE-2021-45046
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
Apache Software Foundation9.0100.0%KEV2021-12-14
CVE-2022-33891
Apache Spark shell command injection vulnerability via Spark UI
Apache Software Foundation8.893.2%KEV2022-07-18
CVE-2022-24112
apisix/batch-requests plugin allows overwriting the X-REAL-IP header
Apache Software Foundation9.896.1%KEV2022-02-11
CVE-2022-24706
Remote Code Execution Vulnerability in Packaging
Apache Software Foundation9.892.5%KEV2022-04-26
CVE-2013-2251
Apache Struts Improper Input Validation Vulnerability
-9.8100.0%KEV2013-07-18
CVE-2017-12617
Apache Tomcat Remote Code Execution Vulnerability
Apache Software Foundation8.1100.0%KEV2017-10-03
CVE-2017-12615
Apache Tomcat on Windows Remote Code Execution Vulnerability
Apache Software Foundation8.199.6%KEV2017-09-19
CVE-2020-1956
Apache Kylin OS Command Injection Vulnerability
Apache8.897.3%KEV2020-05-22
CVE-2020-1938
Apache Tomcat Improper Privilege Management Vulnerability
Apache9.899.3%KEV2020-02-24
CVE-2017-9791
Apache Struts 1 Improper Input Validation Vulnerability
Apache Software Foundation9.898.9%KEV2017-07-10
CVE-2016-3088
Apache ActiveMQ Improper Input Validation Vulnerability
-9.898.5%KEV2016-06-01
CVE-2012-0391
Apache Struts 2 Improper Input Validation Vulnerability
-9.875.6%KEV2012-01-08
CVE-2006-1547
Apache Struts 1 ActionForm Denial-of-Service Vulnerability
-7.554.6%KEV2006-03-30
CVE-2020-13927
Apache Airflow's Experimental API Authentication Bypass
-9.899.8%KEV2020-11-10
CVE-2020-11978
Apache Airflow Command Injection
Apache Software Foundation8.899.2%KEV2020-07-16
CVE-2021-44228
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
Apache Software Foundation10.0100.0%KEV2021-12-10
CVE-2019-0193
Apache Solr DataImportHandler Code Injection Vulnerability
Apache7.283.5%KEV2019-08-01
CVE-2021-40438
mod_proxy SSRF
Apache Software Foundation9.0100.0%KEV2021-09-16
CVE-2017-5638
Apache Struts Remote Code Execution Vulnerability
Apache Software Foundation9.8100.0%KEV2017-03-11
CVE-2021-41773
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
Apache Software Foundation7.5100.0%KEV2021-10-05
CVE-2018-11776
Apache Struts Remote Code Execution Vulnerability
Apache Software Foundation8.1100.0%KEV2018-08-22
CVE-2021-42013
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
Apache Software Foundation9.8100.0%KEV2021-10-07
CVE-2017-9805
Apache Struts Deserialization of Untrusted Data Vulnerability
Apache Software Foundation8.199.4%KEV2017-09-15
CVE-2019-17558
Apache Solr VelocityResponseWriter Plug-In Remote Code Execution Vulnerability
-7.598.6%KEV2019-12-30
CVE-2020-17530
Apache Struts Remote Code Execution Vulnerability
Apache Software Foundation9.895.9%KEV2020-12-11
CVE-2016-4437
Apache Shiro Code Execution Vulnerability
-9.893.0%KEV2016-06-07
CVE-2019-0211
Apache HTTP Server Privilege Escalation Vulnerability
Apache7.865.0%KEV2019-04-08
CVE-2026-23918
Apache HTTP Server: http2: double free and possible RCE on early reset
Apache Software Foundation8.849.7%2026-05-04
CVE-2026-43825
Apache OpenNLP :: Core :: ML :: LibSVM: Unsafe Java Deserialization in SvmDoccatModel
Apache Software Foundation7.313.9%2026-07-06

Frequently Asked Questions

How many Apache vulnerabilities are actively exploited?→

41 Apache CVEs are in the CISA Known Exploited Vulnerabilities catalog as of 2026-10-09. The latest was added on 2026-10-08.

Which Apache vulnerabilities are used in ransomware attacks?→

CISA marks 8 Apache KEV entries as known to be used in ransomware campaigns, including CVE-2023-46604, CVE-2021-45046, CVE-2017-12615, CVE-2021-44228, CVE-2021-40438.

Which Apache products have the most exploited vulnerabilities?→
  • +Struts: 6 CVEs (6 in KEV)
  • +Tomcat: 6 CVEs (6 in KEV)
  • +HTTP Server: 4 CVEs (4 in KEV)
  • +ActiveMQ: 3 CVEs (3 in KEV)
  • +OFBiz: 3 CVEs (3 in KEV)
Where does Apache publish security advisories?→

Apache publishes security advisories at https://www.apache.org/security/. Check the vendor advisory for fixed versions and workarounds before applying updates.

Sources

CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Vendor and product names for exploited CVEs follow the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not affiliated with or endorsed by Apache, MITRE, CISA, or FIRST.