Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4198 articles · 181307 vulns · 37/41 feeds (7d)
← Back to list
8.8
CVE-2026-23918EXPLOITEDPATCHED
apache · http_server

Apache HTTP Server: http2: double free and possible RCE on early reset

Description

Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

Affected Products

VendorProductVersions
apachehttp_server2.4.66

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
apachehttpcert_advisory90%
applemacoscert_advisory90%

References

  • https://httpd.apache.org/security/vulnerabilities_24.html(vendor-advisory)

Related News (15 articles)

Tier B
BSI Advisories2h ago
[NEU] [hoch] Apple macOS (Tahoe, Sonoma und Sequoia): Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR7d ago
Multiples vulnérabilités dans Tenable Security Center (21 juillet 2026)
→ No new info (linked only)
Tier C
Exploit-DB63d ago
[webapps] Apache HTTP Server 2.4.66 - 'mod_http2' Double-Free Denial of Service
→ No new info (linked only)
Tier B
CERT-FR71d ago
Multiples vulnérabilités dans Microsoft Azure Linux (18 mai 2026)
→ No new info (linked only)
Tier D
Help Net Security71d ago
Debian 13.5 point release lands with security fixes, bug patches
→ No new info (linked only)
Tier E
Hacker News79d ago
Our side project: cyber-research-AI IDE, writing an exploit for CVE-2026-23918 [video]
→ No new info (linked only)
Tier A
Microsoft MSRC82d ago
CVE-2026-23918 Apache HTTP Server: http2: double free and possible RCE on early reset
→ No new info (linked only)
Tier E
Hacker News82d ago
For a Fistful of Dollars: CVE-2026-23918 – Pre-auth RCE in Apache httpd
→ No new info (linked only)
Tier D
Heise Security83d ago
Apache HTTP Server: Hochriskante Lücken ermöglichen Einschleusen von Schadcode
→ No new info (linked only)
Tier D
The Hacker News83d ago
Critical Apache HTTP/2 Flaw (CVE-2026-23918) Enables DoS and Potential RCE
→ No new info (linked only)
Tier D
SecurityWeek84d ago
Critical, High-Severity Vulnerabilities Patched in Apache MINA, HTTP Server
→ No new info (linked only)
Tier B
BSI Advisories84d ago
[NEU] [hoch] Apache HTTP Server: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR84d ago
Multiples vulnérabilités dans Apache HTTP Server (05 mai 2026)
→ No new info (linked only)
Tier C
oss-security84d ago
CVE-2026-23918: Apache HTTP Server: http2: double free and possible RCE on early reset
→ No new info (linked only)
Tier C
VulDB84d ago
CVE-2026-23918 | Apache HTTP Server 2.4.66 HTTP/2 double free
→ No new info (linked only)
CVSS 3.18.8 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
https://httpd.apache.org/security/vulnerabilities_24.html
CWECWE-415
PublishedMay 4, 2026
Last enriched62d agov4
Tags
double-freeDenial of Service
Trending Score92
Source articles15
Independent11
Info Completeness10/14
Missing: epss, kev, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-41293EXP
Apache Tomcat: HTTP/2 request headers not validated
Trending: 37
CRITICALCVE-2026-43512
Apache Tomcat: Digest authenticator will authenticate any unknown user
Trending: 36
NONECVE-2026-49975EXP
Apache HTTP Server: mod_http2 denial of service
Trending: 36
HIGHCVE-2026-29167EXP
Apache HTTP Server: mod_ldap per-dir use-after-free
Trending: 35
CRITICALCVE-2026-44631
Apache HTTP Server: Heap Underflow in `ap_regname` via Signed Char Overflow
Trending: 33

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 4, 2026
Discovered by ZDM
May 4, 2026
Updated: affectedVersions
May 5, 2026
Updated: description, exploitAvailable, activelyExploited
May 5, 2026
Updated: description, tags
May 26, 2026
Actively Exploited
Jul 15, 2026
Exploit Available
Jul 15, 2026
Patch Available
Jul 15, 2026

Version History

v4
Last enriched 62d ago
v4Tier C62d ago

Added a detailed description of the vulnerability and new relevant tags.

descriptiontags
via Exploit-DB
v3Tier D83d ago

Updated description with CVE-2026-23918, marked exploit as available, noted it is actively exploited, and indicated no patch version number provided.

descriptionexploitAvailableactivelyExploited
via The Hacker News
v2Tier D84d ago

Updated description with new technical details, marked the vulnerability as CRITICAL, and noted that it is actively exploited.

affectedVersions
via SecurityWeek
v184d ago

Initial creation