Vendor

Apache, page 2

As of , 40 Apache vulnerabilities are on CISA's list of exploited vulnerabilities, 8 of them used in ransomware campaigns; 2 were added in 2026. Patch first: CVE-2020-17519.

#VulnerabilityProductOur groupListedDeadlineEPSS
26CVE-2020-13927Authentication BypassApache Airflow's Experimental APIPatch this weekMetasploit module; EPSS 0.990.99
27CVE-2021-44228Remote Code ExecutionApache Log4j2Patch this weekRansomware use; Metasploit module; EPSS 0.990.99
28CVE-2017-9805Deserialization of Untrusted DataApache StrutsPatch this weekMetasploit module; EPSS 0.990.99
29CVE-2020-17530Remote Code ExecutionApache StrutsPatch this weekMetasploit module; EPSS 0.960.96
30CVE-2026-34197Improper Input ValidationApache ActiveMQPatch this weekMetasploit module0.15
31CVE-2024-38475Improper Escaping of OutputApache HTTP ServerPatch this weekEPSS 0.990.99
32CVE-2024-45195Forced BrowsingApache OFBizPatch this weekEPSS 0.990.99
33CVE-2016-8735Remote Code ExecutionApache TomcatPatch this weekEPSS 0.900.90
34CVE-2017-12615on Windows Remote Code ExecutionApache TomcatPatch this weekRansomware use; EPSS 0.990.99
35CVE-2020-1956OS Command InjectionApache KylinPatch this weekEPSS 0.970.97
36CVE-2019-0193DataImportHandler Code InjectionApache SolrPatch this weekEPSS 0.840.84
37CVE-2021-40438HTTP Server-Side Request Forgery (SSRF)Apache ApachePatch this weekRansomware use; EPSS 0.990.99
38CVE-2019-0211Privilege EscalationApache HTTP ServerPatch this weekEPSS 0.650.65
39CVE-2006-1547ActionForm Denial-of-ServiceApache Struts 1Patch this weekEPSS 0.550.55
40CVE-2026-34486Missing Encryption of Sensitive DataApache TomcatPatch soon0.07