PT-2026-37040 · Apache+3 · Apache Http Server+3

·

CVE-2026-28780

·

Published

2026-02-04

·

Updated

2026-07-09

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions prior to 2.4.67
Description A heap-based buffer overflow exists in the mod proxy ajp module. If mod proxy ajp connects to a malicious AJP server, that server can send a crafted AJP message causing the system to write four attacker-controlled bytes beyond the end of a heap-based buffer, leading to memory corruption.
Recommendations Upgrade to version 2.4.67.

Exploit

Fix

DoS

RCE

Heap Based Buffer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:21391
ALSA-2026:21433
ALSA-2026:22140
BDU:2026-06407
BIT-APACHE-2026-28780
CVE-2026-28780
OESA-2026-2316
OESA-2026-2317
OESA-2026-2318
OESA-2026-2319
OESA-2026-2320
OPENSUSE-SU-2026:10785-1
OPENSUSE-SU-2026:21115-1
RHSA-2026:21391
RHSA-2026:21433
SUSE-SU-2026:2103-1
SUSE-SU-2026:2104-1
SUSE-SU-2026:22199-1
SUSE-SU-2026:22209-1
SUSE-SU-2026:2641-1
SUSE-SU-2026:2686-1
USN-8239-1
USN-8396-1

Affected Products

Apache Http Server
Linuxmint
Rocky Linux
Ubuntu