Brand
Apache: actively exploited vulnerabilities
40 vulnerabilities in Apache products (Struts, Tomcat, HTTP Server…) are in CISA’s catalog of exploited vulnerabilities, 1 of them added in the last 90 days. Last added: August 4, 2026.
The brand’s general security advisories page, not the advisory for a specific vulnerability (address checked September 28, 2026).
-
2 vulnerabilities added in the last 12 months
-
40 exploited vulnerabilities in the catalog, in total
-
0 added in the last 30 days
By category
Add just one Apache category to your radar, or open its page.
- Web and application servers 16 vulnerabilities
- Frameworks and libraries 11 vulnerabilities
- ERP, business applications and databases 11 vulnerabilities
- AI and automation 2 vulnerabilities
A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.
Affected products
- Struts 6 vulnerabilities · Frameworks
- Tomcat 6 vulnerabilities · Web servers
- HTTP Server 5 vulnerabilities · Web servers
- ActiveMQ 3 vulnerabilities · Web servers
- OFBiz 3 vulnerabilities · Business apps and data
- Airflow 2 vulnerabilities · AI and automation
- Log4j 2 vulnerabilities · Frameworks
- Solr 2 vulnerabilities · Business apps and data
- Struts 1 2 vulnerabilities · Frameworks
- APISIX 1 vulnerability · Web servers
- CouchDB 1 vulnerability · Business apps and data
- Flink 1 vulnerability · Business apps and data
Show 6 more products
- HugeGraph 1 vulnerability · Business apps and data
- Kylin 1 vulnerability · Business apps and data
- RocketMQ 1 vulnerability · Web servers
- Shiro 1 vulnerability · Frameworks
- Spark 1 vulnerability · Business apps and data
- Superset 1 vulnerability · Business apps and data
Name used by CISA: Apache. Product families: indicative classification by this site.
Pace of additions
| Period | Vulnerabilities added |
|---|---|
| Sep 4, 2025 to Oct 3, 2025 | 0 |
| Oct 4, 2025 to Nov 2, 2025 | 0 |
| Nov 3, 2025 to Dec 2, 2025 | 0 |
| Dec 3, 2025 to Jan 1, 2026 | 0 |
| Jan 2, 2026 to Jan 31, 2026 | 0 |
| Feb 1, 2026 to Mar 2, 2026 | 0 |
| Mar 3, 2026 to Apr 1, 2026 | 0 |
| Apr 2, 2026 to May 1, 2026 | 1 |
| May 2, 2026 to May 31, 2026 | 0 |
| Jun 1, 2026 to Jun 30, 2026 | 0 |
| Jul 1, 2026 to Jul 30, 2026 | 0 |
| Jul 31, 2026 to Aug 29, 2026 | 1 |
| Aug 30, 2026 to Sep 28, 2026 (in progress) | 0 |
Patch first
In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this Apache list.
Rank 1Apache ActiveMQ
CVE-2026-34197Apache ActiveMQ Improper Input Validation Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Apr 16, 2026
- CISA deadline
- 14 days
- CVSS severity
- 8.8 (high)
Rank 2Apache Tomcat
CVE-2026-34486Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Aug 4, 2026
- CISA deadline
- 3 days
- CVSS severity
- 7.5 (high)
Rank 3Apache Log4j
CVE-2021-44228Ransomware
Apache Log4j2 Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Dec 10, 2021
- CISA deadline
- 14 days
- CVSS severity
- 10.0 (critical)
Rank 4Apache Tomcat
CVE-2025-24813Apache Tomcat Path Equivalence Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Apr 1, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 5Apache HugeGraph
CVE-2024-27348Apache HugeGraph-Server Improper Access Control Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Sep 18, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 6Apache OFBiz
CVE-2024-38856Apache OFBiz Incorrect Authorization Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Aug 27, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 7Apache OFBiz
CVE-2024-32113Apache OFBiz Path Traversal Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Aug 7, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 8Apache Superset
CVE-2023-27524Apache Superset Insecure Default Initialization of Resource Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jan 8, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 9Apache ActiveMQ
CVE-2023-46604Ransomware
Apache ActiveMQ Deserialization of Untrusted Data Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 2, 2023
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 10Apache RocketMQ
CVE-2023-33246Apache RocketMQ Command Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Sep 6, 2023
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Show 30 more vulnerabilities
Rank 11Apache Tomcat
CVE-2016-8735CVE from 2016, added in 2023
Apache Tomcat Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- May 12, 2023
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 12Apache APISIX
CVE-2022-24112Apache APISIX Authentication Bypass Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Aug 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 13Apache CouchDB
CVE-2022-24706Apache CouchDB Insecure Default Initialization of Resource Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Aug 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 14Apache Struts
CVE-2013-2251CVE from 2013, added in 2022
Apache Struts Improper Input Validation Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 15Apache Tomcat
CVE-2020-1938CVE from 2020, added in 2022
Apache Tomcat Improper Privilege Management Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 14 days
- CVSS severity
- 9.8 (critical)
Rank 16Apache ActiveMQ
CVE-2016-3088CVE from 2016, added in 2022
Apache ActiveMQ Improper Input Validation Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Feb 10, 2022
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 17Apache Struts 1
CVE-2017-9791CVE from 2017, added in 2022
Apache Struts 1 Improper Input Validation Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Feb 10, 2022
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 18Apache Struts
CVE-2012-0391CVE from 2012, added in 2022
Apache Struts 2 Improper Input Validation Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jan 21, 2022
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 19Apache Airflow
CVE-2020-13927CVE from 2020, added in 2022
Apache Airflow's Experimental API Authentication Bypass
Added more than a year ago: ranked by severity.
- Added
- Jan 18, 2022
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 20Apache Shiro
CVE-2016-4437CVE from 2016, added in 2021
Apache Shiro Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 21Apache Struts
CVE-2017-5638RansomwareCVE from 2017, added in 2021
Apache Struts Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 22Apache Struts
CVE-2020-17530Apache Struts Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 23Apache HTTP Server
CVE-2021-41773Ransomware
Apache HTTP Server Path Traversal Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 14 days
- CVSS severity
- 9.8 (critical)
Rank 24Apache HTTP Server
CVE-2021-42013Ransomware
Apache HTTP Server Path Traversal Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 14 days
- CVSS severity
- 9.8 (critical)
Rank 25Apache HTTP Server
CVE-2024-38475Apache HTTP Server Improper Escaping of Output Vulnerability
Added more than a year ago: ranked by severity.
- Added
- May 1, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.1 (critical)
Rank 26Apache Log4j
CVE-2021-45046RansomwareCVE from 2021, added in 2023
Apache Log4j2 Deserialization of Untrusted Data Vulnerability
Added more than a year ago: ranked by severity.
- Added
- May 1, 2023
- CISA deadline
- 21 days
- CVSS severity
- 9.0 (critical)
Rank 27Apache HTTP Server
CVE-2021-40438Ransomware
Apache HTTP Server-Side Request Forgery (SSRF)
Added more than a year ago: ranked by severity.
- Added
- Dec 1, 2021
- CISA deadline
- 14 days
- CVSS severity
- 9.0 (critical)
Rank 28Apache Spark
CVE-2022-33891Apache Spark Command Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 7, 2023
- CISA deadline
- 21 days
- CVSS severity
- 8.8 (high)
Rank 29Apache Kylin
CVE-2020-1956CVE from 2020, added in 2022
Apache Kylin OS Command Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 8.8 (high)
Rank 30Apache Airflow
CVE-2020-11978CVE from 2020, added in 2022
Apache Airflow Command Injection
Added more than a year ago: ranked by severity.
- Added
- Jan 18, 2022
- CISA deadline
- 181 days
- CVSS severity
- 8.8 (high)
Rank 31Apache Tomcat
CVE-2017-12615RansomwareCVE from 2017, added in 2022
Apache Tomcat on Windows Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 8.1 (high)
Rank 32Apache Tomcat
CVE-2017-12617CVE from 2017, added in 2022
Apache Tomcat Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 8.1 (high)
Rank 33Apache Struts
CVE-2017-9805CVE from 2017, added in 2021
Apache Struts Deserialization of Untrusted Data Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 8.1 (high)
Rank 34Apache Struts
CVE-2018-11776CVE from 2018, added in 2021
Apache Struts Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 8.1 (high)
Rank 35Apache HTTP Server
CVE-2019-0211CVE from 2019, added in 2021
Apache HTTP Server Privilege Escalation Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 7.8 (high)
Rank 36Apache OFBiz
CVE-2024-45195Apache OFBiz Forced Browsing Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Feb 4, 2025
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 37Apache Flink
CVE-2020-17519CVE from 2020, added in 2024
Apache Flink Improper Access Control Vulnerability
Added more than a year ago: ranked by severity.
- Added
- May 23, 2024
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 38Apache Struts 1
CVE-2006-1547CVE from 2006, added in 2022
Apache Struts 1 ActionForm Denial-of-Service Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jan 21, 2022
- CISA deadline
- 181 days
- CVSS severity
- 7.5 (high)
Rank 39Apache Solr
CVE-2019-17558CVE from 2019, added in 2021
Apache Solr VelocityResponseWriter Plug-In Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 7.5 (high)
Rank 40Apache Solr
CVE-2019-0193CVE from 2019, added in 2021
Apache Solr DataImportHandler Code Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Dec 10, 2021
- CISA deadline
- 182 days
- CVSS severity
- 7.2 (high)
Follow and verify
Get new Apache vulnerabilities: RSS feed (add it to Outlook, Teams, Slack or your feed reader).
Indicative classification, based on the vendor and product names given by CISA. How products are classified.