CVE-2026-28780
A heap-based buffer overflow exists in Apache HTTP Server's mod_proxy_ajp module. If the server connects to a malicious AJP server, the attacker can send crafted data that causes Apache to write attacker-controlled bytes beyond a heap buffer. This can lead to arbitrary code execution.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Apache HTTP Server 2.4.66 and earlier, especially installations that enable mod_proxy_ajp.
Real-world impact
An attacker who can make the server talk to a malicious AJP server can overwrite memory, potentially taking control of the server and executing arbitrary code.
Why this severity
The CVSS score of 9.8 reflects that the flaw requires no authentication, can be triggered remotely, and gives an attacker full control over confidentiality, integrity, and availability.
What to do about it
- 01Upgrade Apache HTTP Server to version 2.4.67 or later.
- 02Restart the Apache service to apply the update.
NVD-referenced vendor advisory
Timeline
- May 5, 2026 · May 5, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 26, 2026 · 10d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
- Jul 28, 2026 · 8d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- httpd.apache.org/security/vulnerabilities_24…release notesvendor advisory
- openwall.com/lists/oss-security/2026/05/…mailing listthird party advisory
- access.redhat.com/errata/RHSA-2026:21391
- access.redhat.com/errata/RHSA-2026:21433
- access.redhat.com/errata/RHSA-2026:22140
- access.redhat.com/errata/RHSA-2026:27200
- access.redhat.com/errata/RHSA-2026:27201
- access.redhat.com/errata/RHSA-2026:36373
- access.redhat.com/errata/RHSA-2026:36831
- access.redhat.com/errata/RHSA-2026:36846
- access.redhat.com/errata/RHSA-2026:47046
- access.redhat.com/security/cve/CVE-2026-28780
- bugzilla.redhat.com/show_bug.cgi
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2…