Skip to content

Products › Brands

Brand

Apache: actively exploited vulnerabilities

40 vulnerabilities in Apache products (Struts, Tomcat, HTTP Server…) are in CISA’s catalog of exploited vulnerabilities, 1 of them added in the last 90 days. Last added: August 4, 2026.

The brand’s general security advisories page, not the advisory for a specific vulnerability (address checked September 28, 2026).

By category

Add just one Apache category to your radar, or open its page.

A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.

Affected products

Follow a single Apache product (Struts, Tomcat…) rather than the whole brand.

  • Struts6 vulnerabilities, Frameworks
  • Tomcat6 vulnerabilities, Web servers
  • HTTP Server5 vulnerabilities, Web servers
  • ActiveMQ3 vulnerabilities, Web servers
  • OFBiz3 vulnerabilities, Business apps and data
  • Airflow2 vulnerabilities, AI and automation
  • Log4j2 vulnerabilities, Frameworks
  • Solr2 vulnerabilities, Business apps and data
  • Struts 12 vulnerabilities, Frameworks
  • APISIX1 vulnerability, Web servers
  • CouchDB1 vulnerability, Business apps and data
  • Flink1 vulnerability, Business apps and data
Show 6 more products
  • HugeGraph1 vulnerability, Business apps and data
  • Kylin1 vulnerability, Business apps and data
  • RocketMQ1 vulnerability, Web servers
  • Shiro1 vulnerability, Frameworks
  • Spark1 vulnerability, Business apps and data
  • Superset1 vulnerability, Business apps and data

Name used by CISA: Apache. Product families: indicative classification by this site.

Pace of additions

Number of Apache vulnerabilities added to CISA’s KEV catalog, per 30-day period (the last one, still in progress, ends on October 3, 2026). Source: CISA KEV catalog.
Catalog additions per 30-day period
PeriodVulnerabilities added
Sep 9, 2025 to Oct 8, 20250
Oct 9, 2025 to Nov 7, 20250
Nov 8, 2025 to Dec 7, 20250
Dec 8, 2025 to Jan 6, 20260
Jan 7, 2026 to Feb 5, 20260
Feb 6, 2026 to Mar 7, 20260
Mar 8, 2026 to Apr 6, 20260
Apr 7, 2026 to May 6, 20261
May 7, 2026 to Jun 5, 20260
Jun 6, 2026 to Jul 5, 20260
Jul 6, 2026 to Aug 4, 20261
Aug 5, 2026 to Sep 3, 20260
Sep 4, 2026 to Oct 3, 2026 (in progress)0

Patch first

In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this Apache list.

  1. Rank 1

    Apache ActiveMQCVE-2026-34197

    Apache ActiveMQ Improper Input Validation Vulnerability

    CVSS severity 8.8high

    Added Apr 16, 2026

  2. Rank 2

    Apache TomcatCVE-2026-34486

    Apache Tomcat Missing Encryption of Sensitive Data Vulnerability

    CVSS severity 7.5high

    Added Aug 4, 2026

  3. Rank 3

    Apache Log4jCVE-2021-44228

    Apache Log4j2 Remote Code Execution Vulnerability

    Ransomware

    CVSS severity 10.0critical

    Added Dec 10, 2021

  4. Rank 4

    Apache TomcatCVE-2025-24813

    Apache Tomcat Path Equivalence Vulnerability

    CVSS severity 9.8critical

    Added Apr 1, 2025

  5. Rank 5

    Apache HugeGraphCVE-2024-27348

    Apache HugeGraph-Server Improper Access Control Vulnerability

    CVSS severity 9.8critical

    Added Sep 18, 2024

  6. Rank 6

    Apache OFBizCVE-2024-38856

    Apache OFBiz Incorrect Authorization Vulnerability

    CVSS severity 9.8critical

    Added Aug 27, 2024

  7. Rank 7

    Apache OFBizCVE-2024-32113

    Apache OFBiz Path Traversal Vulnerability

    CVSS severity 9.8critical

    Added Aug 7, 2024

  8. Rank 8

    Apache SupersetCVE-2023-27524

    Apache Superset Insecure Default Initialization of Resource Vulnerability

    CVSS severity 9.8critical

    Added Jan 8, 2024

  9. Rank 9

    Apache ActiveMQCVE-2023-46604

    Apache ActiveMQ Deserialization of Untrusted Data Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added Nov 2, 2023

  10. Rank 10

    Apache RocketMQCVE-2023-33246

    Apache RocketMQ Command Execution Vulnerability

    CVSS severity 9.8critical

    Added Sep 6, 2023

Show 30 more vulnerabilities
  1. Rank 11

    Apache TomcatCVE-2016-8735

    Apache Tomcat Remote Code Execution Vulnerability

    CVE from 2016, added in 2023

    CVSS severity 9.8critical

    Added May 12, 2023

  2. Rank 12

    Apache APISIXCVE-2022-24112

    Apache APISIX Authentication Bypass Vulnerability

    CVSS severity 9.8critical

    Added Aug 25, 2022

  3. Rank 13

    Apache CouchDBCVE-2022-24706

    Apache CouchDB Insecure Default Initialization of Resource Vulnerability

    CVSS severity 9.8critical

    Added Aug 25, 2022

  4. Rank 14

    Apache StrutsCVE-2013-2251

    Apache Struts Improper Input Validation Vulnerability

    CVE from 2013, added in 2022

    CVSS severity 9.8critical

    Added Mar 25, 2022

  5. Rank 15

    Apache TomcatCVE-2020-1938

    Apache Tomcat Improper Privilege Management Vulnerability

    CVE from 2020, added in 2022

    CVSS severity 9.8critical

    Added Mar 3, 2022

  6. Rank 16

    Apache ActiveMQCVE-2016-3088

    Apache ActiveMQ Improper Input Validation Vulnerability

    CVE from 2016, added in 2022

    CVSS severity 9.8critical

    Added Feb 10, 2022

  7. Rank 17

    Apache Struts 1CVE-2017-9791

    Apache Struts 1 Improper Input Validation Vulnerability

    CVE from 2017, added in 2022

    CVSS severity 9.8critical

    Added Feb 10, 2022

  8. Rank 18

    Apache StrutsCVE-2012-0391

    Apache Struts 2 Improper Input Validation Vulnerability

    CVE from 2012, added in 2022

    CVSS severity 9.8critical

    Added Jan 21, 2022

  9. Rank 19

    Apache AirflowCVE-2020-13927

    Apache Airflow's Experimental API Authentication Bypass

    CVE from 2020, added in 2022

    CVSS severity 9.8critical

    Added Jan 18, 2022

  10. Rank 20

    Apache ShiroCVE-2016-4437

    Apache Shiro Code Execution Vulnerability

    CVE from 2016, added in 2021

    CVSS severity 9.8critical

    Added Nov 3, 2021

  11. Rank 21

    Apache StrutsCVE-2017-5638

    Apache Struts Remote Code Execution Vulnerability

    RansomwareCVE from 2017, added in 2021

    CVSS severity 9.8critical

    Added Nov 3, 2021

  12. Rank 22

    Apache StrutsCVE-2020-17530

    Apache Struts Remote Code Execution Vulnerability

    CVSS severity 9.8critical

    Added Nov 3, 2021

  13. Rank 23

    Apache HTTP ServerCVE-2021-41773

    Apache HTTP Server Path Traversal Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added Nov 3, 2021

  14. Rank 24

    Apache HTTP ServerCVE-2021-42013

    Apache HTTP Server Path Traversal Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added Nov 3, 2021

  15. Rank 25

    Apache HTTP ServerCVE-2024-38475

    Apache HTTP Server Improper Escaping of Output Vulnerability

    CVSS severity 9.1critical

    Added May 1, 2025

  16. Rank 26

    Apache Log4jCVE-2021-45046

    Apache Log4j2 Deserialization of Untrusted Data Vulnerability

    RansomwareCVE from 2021, added in 2023

    CVSS severity 9.0critical

    Added May 1, 2023

  17. Rank 27

    Apache HTTP ServerCVE-2021-40438

    Apache HTTP Server-Side Request Forgery (SSRF)

    Ransomware

    CVSS severity 9.0critical

    Added Dec 1, 2021

  18. Rank 28

    Apache SparkCVE-2022-33891

    Apache Spark Command Injection Vulnerability

    CVSS severity 8.8high

    Added Mar 7, 2023

  19. Rank 29

    Apache KylinCVE-2020-1956

    Apache Kylin OS Command Injection Vulnerability

    CVE from 2020, added in 2022

    CVSS severity 8.8high

    Added Mar 25, 2022

  20. Rank 30

    Apache AirflowCVE-2020-11978

    Apache Airflow Command Injection

    CVE from 2020, added in 2022

    CVSS severity 8.8high

    Added Jan 18, 2022

  21. Rank 31

    Apache TomcatCVE-2017-12615

    Apache Tomcat on Windows Remote Code Execution Vulnerability

    RansomwareCVE from 2017, added in 2022

    CVSS severity 8.1high

    Added Mar 25, 2022

  22. Rank 32

    Apache TomcatCVE-2017-12617

    Apache Tomcat Remote Code Execution Vulnerability

    CVE from 2017, added in 2022

    CVSS severity 8.1high

    Added Mar 25, 2022

  23. Rank 33

    Apache StrutsCVE-2017-9805

    Apache Struts Deserialization of Untrusted Data Vulnerability

    CVE from 2017, added in 2021

    CVSS severity 8.1high

    Added Nov 3, 2021

  24. Rank 34

    Apache StrutsCVE-2018-11776

    Apache Struts Remote Code Execution Vulnerability

    CVE from 2018, added in 2021

    CVSS severity 8.1high

    Added Nov 3, 2021

  25. Rank 35

    Apache HTTP ServerCVE-2019-0211

    Apache HTTP Server Privilege Escalation Vulnerability

    CVE from 2019, added in 2021

    CVSS severity 7.8high

    Added Nov 3, 2021

  26. Rank 36

    Apache OFBizCVE-2024-45195

    Apache OFBiz Forced Browsing Vulnerability

    CVSS severity 7.5high

    Added Feb 4, 2025

  27. Rank 37

    Apache FlinkCVE-2020-17519

    Apache Flink Improper Access Control Vulnerability

    CVE from 2020, added in 2024

    CVSS severity 7.5high

    Added May 23, 2024

  28. Rank 38

    Apache Struts 1CVE-2006-1547

    Apache Struts 1 ActionForm Denial-of-Service Vulnerability

    CVE from 2006, added in 2022

    CVSS severity 7.5high

    Added Jan 21, 2022

  29. Rank 39

    Apache SolrCVE-2019-17558

    Apache Solr VelocityResponseWriter Plug-In Remote Code Execution Vulnerability

    CVE from 2019, added in 2021

    CVSS severity 7.5high

    Added Nov 3, 2021

  30. Rank 40

    Apache SolrCVE-2019-0193

    Apache Solr DataImportHandler Code Injection Vulnerability

    CVE from 2019, added in 2021

    CVSS severity 7.2high

    Added Dec 10, 2021

Follow and verify

Get new Apache vulnerabilities: RSS feed (add it to Outlook, Teams, Slack or your feed reader).

Indicative classification, based on the vendor and product names given by CISA. How products are classified.