Exposición de Apache HTTP Server

Web servers
561
score de exposición
1.580.941
sitios usan
5
en explotación
20
críticos
Análisis Vexday

O Apache HTTP Server acumula 169 CVEs catalogadas, com 16 classificadas como críticas e 34 surgidas apenas nos últimos 90 dias, sinalizando um ritmo elevado de descobertas recentes que exige atenção contínua. A taxa de exploração ativa é 6,6 vezes acima da média geral do catálogo CISA KEV, com 5 vulnerabilidades confirmadas em uso por agentes de ameaça — proporção que coloca o servidor entre as tecnologias de maior risco operacional imediato. A CVE mais perigosa atualmente ativa, CVE-2021-40438, apresenta EPSS de 1,0, o valor máximo possível, indicando probabilidade praticamente certa de exploração observada no ambiente real. O tipo de falha mais recorrente é CWE-476 (desreferência de ponteiro nulo), embora o perfil de risco mais crítico esteja nas vulnerabilidades com exploração confirmada, que devem ser priorizadas em qualquer plano de remediação.

CVEs

178 resultados
CVE-2026-33006MEDIUMApache HTTP Server: mod_auth_digest timing attackEPSS 0.6%CVE-2026-43951MEDIUMApache HTTP Server: OOB Read in `merge_response_headers` can cause crashEPSS 0.5%CVE-2026-42535CRITICALApache HTTP Server: mod_dav_fs protected directory accessEPSS 0.5%CVE-2026-29170MEDIUMApache HTTP Server: mod_proxy_ftp XSSEPSS 0.5%CVE-2025-49812HIGHApache HTTP Server: mod_ssl TLS upgrade attackEPSS 0.5%CVE-2026-33007MEDIUMApache HTTP Server: mod_authn_socache crashEPSS 0.5%CVE-2023-22019HIGHVulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Web Listener). The supported version that is affecEPSS 0.5%CVE-2026-44631CRITICALApache HTTP Server: Heap Underflow in `ap_regname` via Signed Char OverflowEPSS 0.5%CVE-2025-21498MEDIUMVulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 1EPSS 0.5%CVE-2021-3688A flaw was found in Red Hat JBoss Core Services HTTP Server in all versions, where it does not properly normalize the path component of a reEPSS 0.5%CVE-2026-9170CRITICALIBM HTTP Server is affected by multiple vulnerabilitiesEPSS 0.5%CVE-2026-34032MEDIUMApache HTTP Server: mod_proxy_ajp: Heap Buffer Over-Read Due to Missing Null-Termination Check (ajp_msg_get_string)EPSS 0.5%CVE-2026-48913HIGHApache HTTP Server: mod_http2 memory corruption when file handles exhaustedEPSS 0.5%CVE-2026-8855HIGHIBM HTTP Server is affected by multiple vulnerabilitiesEPSS 0.5%CVE-2019-2414Vulnerability in the Oracle HTTP Server component of Oracle Fusion Middleware (subcomponent: Web Listener). The supported version that is afEPSS 0.5%CVE-2025-55753HIGHApache HTTP Server: mod_md (ACME), unintended retry intervalsEPSS 0.4%CVE-2026-33523MEDIUMApache HTTP Server: multiple modules: HTTP response splitting forwarding malicious status lineEPSS 0.4%CVE-2026-16756HIGHAllocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of serviceEPSS 0.4%CVE-2026-60365CRITICALVulnerability in the Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: WebLogic Server Proxy Plug-In for EPSS 0.4%CVE-2026-34059HIGHApache HTTP Server: mod_proxy_ajp: Heap Over-Read and memory disclosure in ajp_parse_data()EPSS 0.4%