Vendor
Apache, page 2
As of , 40 Apache vulnerabilities are on CISA's list of exploited vulnerabilities, 8 of them used in ransomware campaigns; 2 were added in 2026. Patch first: CVE-2020-17519.
| # | Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|---|
| 26 | CVE-2020-13927Authentication Bypass | Apache Airflow's Experimental API | Patch this weekMetasploit module; EPSS 0.99 | 0.99 | ||
| 27 | CVE-2021-44228Remote Code Execution | Apache Log4j2 | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 28 | CVE-2017-9805Deserialization of Untrusted Data | Apache Struts | Patch this weekMetasploit module; EPSS 0.99 | 0.99 | ||
| 29 | CVE-2020-17530Remote Code Execution | Apache Struts | Patch this weekMetasploit module; EPSS 0.96 | 0.96 | ||
| 30 | CVE-2026-34197Improper Input Validation | Apache ActiveMQ | Patch this weekMetasploit module | 0.15 | ||
| 31 | CVE-2024-38475Improper Escaping of Output | Apache HTTP Server | Patch this weekEPSS 0.99 | 0.99 | ||
| 32 | CVE-2024-45195Forced Browsing | Apache OFBiz | Patch this weekEPSS 0.99 | 0.99 | ||
| 33 | CVE-2016-8735Remote Code Execution | Apache Tomcat | Patch this weekEPSS 0.90 | 0.90 | ||
| 34 | CVE-2017-12615on Windows Remote Code Execution | Apache Tomcat | Patch this weekRansomware use; EPSS 0.99 | 0.99 | ||
| 35 | CVE-2020-1956OS Command Injection | Apache Kylin | Patch this weekEPSS 0.97 | 0.97 | ||
| 36 | CVE-2019-0193DataImportHandler Code Injection | Apache Solr | Patch this weekEPSS 0.84 | 0.84 | ||
| 37 | CVE-2021-40438HTTP Server-Side Request Forgery (SSRF) | Apache Apache | Patch this weekRansomware use; EPSS 0.99 | 0.99 | ||
| 38 | CVE-2019-0211Privilege Escalation | Apache HTTP Server | Patch this weekEPSS 0.65 | 0.65 | ||
| 39 | CVE-2006-1547ActionForm Denial-of-Service | Apache Struts 1 | Patch this weekEPSS 0.55 | 0.55 | ||
| 40 | CVE-2026-34486Missing Encryption of Sensitive Data | Apache Tomcat | Patch soon | 0.07 |