Brand
Apache: actively exploited vulnerabilities
40 vulnerabilities in Apache products (Struts, Tomcat, HTTP Server…) are in CISA’s catalog of exploited vulnerabilities, 1 of them added in the last 90 days. Last added: August 4, 2026.
The brand’s general security advisories page, not the advisory for a specific vulnerability (address checked September 28, 2026).
-
2 vulnerabilities added in the last 12 months
-
40 exploited vulnerabilities in the catalog, in total
-
0 added in the last 30 days
By category
Add just one Apache category to your radar, or open its page.
- Web and application servers 16 vulnerabilities
- Frameworks and libraries 11 vulnerabilities
- ERP, business applications and databases 11 vulnerabilities
- AI and automation 2 vulnerabilities
A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.
Affected products
Follow a single Apache product (Struts, Tomcat…) rather than the whole brand.
- Struts6 vulnerabilities, Frameworks
- Tomcat6 vulnerabilities, Web servers
- HTTP Server5 vulnerabilities, Web servers
- ActiveMQ3 vulnerabilities, Web servers
- OFBiz3 vulnerabilities, Business apps and data
- Airflow2 vulnerabilities, AI and automation
- Log4j2 vulnerabilities, Frameworks
- Solr2 vulnerabilities, Business apps and data
- Struts 12 vulnerabilities, Frameworks
- APISIX1 vulnerability, Web servers
- CouchDB1 vulnerability, Business apps and data
- Flink1 vulnerability, Business apps and data
Show 6 more products
- HugeGraph1 vulnerability, Business apps and data
- Kylin1 vulnerability, Business apps and data
- RocketMQ1 vulnerability, Web servers
- Shiro1 vulnerability, Frameworks
- Spark1 vulnerability, Business apps and data
- Superset1 vulnerability, Business apps and data
Name used by CISA: Apache. Product families: indicative classification by this site.
Pace of additions
| Period | Vulnerabilities added |
|---|---|
| Sep 9, 2025 to Oct 8, 2025 | 0 |
| Oct 9, 2025 to Nov 7, 2025 | 0 |
| Nov 8, 2025 to Dec 7, 2025 | 0 |
| Dec 8, 2025 to Jan 6, 2026 | 0 |
| Jan 7, 2026 to Feb 5, 2026 | 0 |
| Feb 6, 2026 to Mar 7, 2026 | 0 |
| Mar 8, 2026 to Apr 6, 2026 | 0 |
| Apr 7, 2026 to May 6, 2026 | 1 |
| May 7, 2026 to Jun 5, 2026 | 0 |
| Jun 6, 2026 to Jul 5, 2026 | 0 |
| Jul 6, 2026 to Aug 4, 2026 | 1 |
| Aug 5, 2026 to Sep 3, 2026 | 0 |
| Sep 4, 2026 to Oct 3, 2026 (in progress) | 0 |
Patch first
In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this Apache list.
- Rank 1
Apache ActiveMQCVE-2026-34197
Apache ActiveMQ Improper Input Validation Vulnerability
CVSS severity 8.8high
Added Apr 16, 2026
- Rank 2
Apache TomcatCVE-2026-34486
Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
CVSS severity 7.5high
Added Aug 4, 2026
- Rank 3
Apache Log4jCVE-2021-44228
Apache Log4j2 Remote Code Execution Vulnerability
Ransomware
CVSS severity 10.0critical
Added Dec 10, 2021
- Rank 4
Apache TomcatCVE-2025-24813
Apache Tomcat Path Equivalence Vulnerability
CVSS severity 9.8critical
Added Apr 1, 2025
- Rank 5
Apache HugeGraphCVE-2024-27348
Apache HugeGraph-Server Improper Access Control Vulnerability
CVSS severity 9.8critical
Added Sep 18, 2024
- Rank 6
Apache OFBizCVE-2024-38856
Apache OFBiz Incorrect Authorization Vulnerability
CVSS severity 9.8critical
Added Aug 27, 2024
- Rank 7
Apache OFBizCVE-2024-32113
Apache OFBiz Path Traversal Vulnerability
CVSS severity 9.8critical
Added Aug 7, 2024
- Rank 8
Apache SupersetCVE-2023-27524
Apache Superset Insecure Default Initialization of Resource Vulnerability
CVSS severity 9.8critical
Added Jan 8, 2024
- Rank 9
Apache ActiveMQCVE-2023-46604
Apache ActiveMQ Deserialization of Untrusted Data Vulnerability
Ransomware
CVSS severity 9.8critical
Added Nov 2, 2023
- Rank 10
Apache RocketMQCVE-2023-33246
Apache RocketMQ Command Execution Vulnerability
CVSS severity 9.8critical
Added Sep 6, 2023
Show 30 more vulnerabilities
- Rank 11
Apache TomcatCVE-2016-8735
Apache Tomcat Remote Code Execution Vulnerability
CVE from 2016, added in 2023
CVSS severity 9.8critical
Added May 12, 2023
- Rank 12
Apache APISIXCVE-2022-24112
Apache APISIX Authentication Bypass Vulnerability
CVSS severity 9.8critical
Added Aug 25, 2022
- Rank 13
Apache CouchDBCVE-2022-24706
Apache CouchDB Insecure Default Initialization of Resource Vulnerability
CVSS severity 9.8critical
Added Aug 25, 2022
- Rank 14
Apache StrutsCVE-2013-2251
Apache Struts Improper Input Validation Vulnerability
CVE from 2013, added in 2022
CVSS severity 9.8critical
Added Mar 25, 2022
- Rank 15
Apache TomcatCVE-2020-1938
Apache Tomcat Improper Privilege Management Vulnerability
CVE from 2020, added in 2022
CVSS severity 9.8critical
Added Mar 3, 2022
- Rank 16
Apache ActiveMQCVE-2016-3088
Apache ActiveMQ Improper Input Validation Vulnerability
CVE from 2016, added in 2022
CVSS severity 9.8critical
Added Feb 10, 2022
- Rank 17
Apache Struts 1CVE-2017-9791
Apache Struts 1 Improper Input Validation Vulnerability
CVE from 2017, added in 2022
CVSS severity 9.8critical
Added Feb 10, 2022
- Rank 18
Apache StrutsCVE-2012-0391
Apache Struts 2 Improper Input Validation Vulnerability
CVE from 2012, added in 2022
CVSS severity 9.8critical
Added Jan 21, 2022
- Rank 19
Apache AirflowCVE-2020-13927
Apache Airflow's Experimental API Authentication Bypass
CVE from 2020, added in 2022
CVSS severity 9.8critical
Added Jan 18, 2022
- Rank 20
Apache ShiroCVE-2016-4437
Apache Shiro Code Execution Vulnerability
CVE from 2016, added in 2021
CVSS severity 9.8critical
Added Nov 3, 2021
- Rank 21
Apache StrutsCVE-2017-5638
Apache Struts Remote Code Execution Vulnerability
RansomwareCVE from 2017, added in 2021
CVSS severity 9.8critical
Added Nov 3, 2021
- Rank 22
Apache StrutsCVE-2020-17530
Apache Struts Remote Code Execution Vulnerability
CVSS severity 9.8critical
Added Nov 3, 2021
- Rank 23
Apache HTTP ServerCVE-2021-41773
Apache HTTP Server Path Traversal Vulnerability
Ransomware
CVSS severity 9.8critical
Added Nov 3, 2021
- Rank 24
Apache HTTP ServerCVE-2021-42013
Apache HTTP Server Path Traversal Vulnerability
Ransomware
CVSS severity 9.8critical
Added Nov 3, 2021
- Rank 25
Apache HTTP ServerCVE-2024-38475
Apache HTTP Server Improper Escaping of Output Vulnerability
CVSS severity 9.1critical
Added May 1, 2025
- Rank 26
Apache Log4jCVE-2021-45046
Apache Log4j2 Deserialization of Untrusted Data Vulnerability
RansomwareCVE from 2021, added in 2023
CVSS severity 9.0critical
Added May 1, 2023
- Rank 27
Apache HTTP ServerCVE-2021-40438
Apache HTTP Server-Side Request Forgery (SSRF)
Ransomware
CVSS severity 9.0critical
Added Dec 1, 2021
- Rank 28
Apache SparkCVE-2022-33891
Apache Spark Command Injection Vulnerability
CVSS severity 8.8high
Added Mar 7, 2023
- Rank 29
Apache KylinCVE-2020-1956
Apache Kylin OS Command Injection Vulnerability
CVE from 2020, added in 2022
CVSS severity 8.8high
Added Mar 25, 2022
- Rank 30
Apache AirflowCVE-2020-11978
Apache Airflow Command Injection
CVE from 2020, added in 2022
CVSS severity 8.8high
Added Jan 18, 2022
- Rank 31
Apache TomcatCVE-2017-12615
Apache Tomcat on Windows Remote Code Execution Vulnerability
RansomwareCVE from 2017, added in 2022
CVSS severity 8.1high
Added Mar 25, 2022
- Rank 32
Apache TomcatCVE-2017-12617
Apache Tomcat Remote Code Execution Vulnerability
CVE from 2017, added in 2022
CVSS severity 8.1high
Added Mar 25, 2022
- Rank 33
Apache StrutsCVE-2017-9805
Apache Struts Deserialization of Untrusted Data Vulnerability
CVE from 2017, added in 2021
CVSS severity 8.1high
Added Nov 3, 2021
- Rank 34
Apache StrutsCVE-2018-11776
Apache Struts Remote Code Execution Vulnerability
CVE from 2018, added in 2021
CVSS severity 8.1high
Added Nov 3, 2021
- Rank 35
Apache HTTP ServerCVE-2019-0211
Apache HTTP Server Privilege Escalation Vulnerability
CVE from 2019, added in 2021
CVSS severity 7.8high
Added Nov 3, 2021
- Rank 36
Apache OFBizCVE-2024-45195
Apache OFBiz Forced Browsing Vulnerability
CVSS severity 7.5high
Added Feb 4, 2025
- Rank 37
Apache FlinkCVE-2020-17519
Apache Flink Improper Access Control Vulnerability
CVE from 2020, added in 2024
CVSS severity 7.5high
Added May 23, 2024
- Rank 38
Apache Struts 1CVE-2006-1547
Apache Struts 1 ActionForm Denial-of-Service Vulnerability
CVE from 2006, added in 2022
CVSS severity 7.5high
Added Jan 21, 2022
- Rank 39
Apache SolrCVE-2019-17558
Apache Solr VelocityResponseWriter Plug-In Remote Code Execution Vulnerability
CVE from 2019, added in 2021
CVSS severity 7.5high
Added Nov 3, 2021
- Rank 40
Apache SolrCVE-2019-0193
Apache Solr DataImportHandler Code Injection Vulnerability
CVE from 2019, added in 2021
CVSS severity 7.2high
Added Dec 10, 2021
Follow and verify
Get new Apache vulnerabilities: RSS feed (add it to Outlook, Teams, Slack or your feed reader).
Indicative classification, based on the vendor and product names given by CISA. How products are classified.