Exposición de Apache HTTP Server

Web servers
595
score de exposición
1.580.941
sitios usan
5
en explotación
20
críticos
Análisis Vexday

O Apache HTTP Server acumula 169 CVEs catalogadas, com 16 classificadas como críticas e 34 surgidas apenas nos últimos 90 dias, sinalizando um ritmo elevado de descobertas recentes que exige atenção contínua. A taxa de exploração ativa é 6,6 vezes acima da média geral do catálogo CISA KEV, com 5 vulnerabilidades confirmadas em uso por agentes de ameaça — proporção que coloca o servidor entre as tecnologias de maior risco operacional imediato. A CVE mais perigosa atualmente ativa, CVE-2021-40438, apresenta EPSS de 1,0, o valor máximo possível, indicando probabilidade praticamente certa de exploração observada no ambiente real. O tipo de falha mais recorrente é CWE-476 (desreferência de ponteiro nulo), embora o perfil de risco mais crítico esteja nas vulnerabilidades com exploração confirmada, que devem ser priorizadas em qualquer plano de remediação.

CVEs

178 resultados
CVE-2026-8850HIGHIBM HTTP Server is affected by multiple vulnerabilitiesEPSS 0.4%CVE-2026-60365CRITICALVulnerability in the Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: WebLogic Server Proxy Plug-In for EPSS 0.4%CVE-2024-21545HIGHProxmox Virtual Environment is an open-source server management platform for enterprise virtualization. Insufficient safeguards against maliEPSS 0.4%CVE-2026-8854HIGHIBM HTTP Server is affected by multiple vulnerabilitiesEPSS 0.4%CVE-2026-60364CRITICALVulnerability in the Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: WebLogic Server Proxy Plug-In for EPSS 0.3%CVE-2026-60363CRITICALVulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Apache Plugin). Supported versions that are affecteEPSS 0.3%CVE-2026-60431HIGHVulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: mod_proxy). Supported versions that are affected arEPSS 0.3%CVE-2026-60438CRITICALVulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: mod_ssl). Supported versions that are affected are EPSS 0.3%CVE-2026-34291HIGHVulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.EPSS 0.3%CVE-2026-8834HIGHIBM HTTP Server is affected by multiple vulnerabilitiesEPSS 0.3%CVE-2026-8835HIGHIBM HTTP Server is affected by multiple vulnerabilitiesEPSS 0.3%CVE-2026-40255MEDIUM@adonisjs/http-server has an Open Redirect vulnerabilityEPSS 0.2%CVE-2026-8856HIGHIBM HTTP Server is affected by multiple vulnerabilitiesEPSS 0.2%CVE-2026-8852MEDIUMIBM HTTP Server is affected by multiple vulnerabilitiesEPSS 0.2%CVE-2026-61526MEDIUMAdonisJS HTTP Server is vulnerable to reflected XSS through its exception handlerEPSS 0.2%CVE-2026-44119MEDIUMApache HTTP Server: escalation of privilege through expressions in .htaccess in multiple modulesEPSS 0.2%CVE-2026-60530HIGHVulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: mod_http2.so). The supported version that is affecEPSS 0.1%CVE-2026-60454HIGHVulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.EPSS 0.1%