Skip to content
English

Products › Brands

Brand

Apache: actively exploited vulnerabilities

40 vulnerabilities in Apache products (Struts, Tomcat, HTTP Server…) are in CISA’s catalog of exploited vulnerabilities, 1 of them added in the last 90 days. Last added: August 4, 2026.

The brand’s general security advisories page, not the advisory for a specific vulnerability (address checked September 28, 2026).

By category

Add just one Apache category to your radar, or open its page.

A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.

Affected products

  • Struts 6 vulnerabilities · Frameworks
  • Tomcat 6 vulnerabilities · Web servers
  • HTTP Server 5 vulnerabilities · Web servers
  • ActiveMQ 3 vulnerabilities · Web servers
  • OFBiz 3 vulnerabilities · Business apps and data
  • Airflow 2 vulnerabilities · AI and automation
  • Log4j 2 vulnerabilities · Frameworks
  • Solr 2 vulnerabilities · Business apps and data
  • Struts 1 2 vulnerabilities · Frameworks
  • APISIX 1 vulnerability · Web servers
  • CouchDB 1 vulnerability · Business apps and data
  • Flink 1 vulnerability · Business apps and data
Show 6 more products
  • HugeGraph 1 vulnerability · Business apps and data
  • Kylin 1 vulnerability · Business apps and data
  • RocketMQ 1 vulnerability · Web servers
  • Shiro 1 vulnerability · Frameworks
  • Spark 1 vulnerability · Business apps and data
  • Superset 1 vulnerability · Business apps and data

Name used by CISA: Apache. Product families: indicative classification by this site.

Pace of additions

Number of Apache vulnerabilities added to CISA’s KEV catalog, per 30-day period (the last one, still in progress, ends on September 28, 2026). Source: CISA KEV catalog.
Catalog additions per 30-day period
PeriodVulnerabilities added
Sep 4, 2025 to Oct 3, 20250
Oct 4, 2025 to Nov 2, 20250
Nov 3, 2025 to Dec 2, 20250
Dec 3, 2025 to Jan 1, 20260
Jan 2, 2026 to Jan 31, 20260
Feb 1, 2026 to Mar 2, 20260
Mar 3, 2026 to Apr 1, 20260
Apr 2, 2026 to May 1, 20261
May 2, 2026 to May 31, 20260
Jun 1, 2026 to Jun 30, 20260
Jul 1, 2026 to Jul 30, 20260
Jul 31, 2026 to Aug 29, 20261
Aug 30, 2026 to Sep 28, 2026 (in progress)0

Patch first

In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this Apache list.

  1. Rank 1Apache ActiveMQ

    CVE-2026-34197

    Apache ActiveMQ Improper Input Validation Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 16, 2026
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  2. Rank 2Apache Tomcat

    CVE-2026-34486

    Apache Tomcat Missing Encryption of Sensitive Data Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Aug 4, 2026
    CISA deadline
    3 days
    CVSS severity
    7.5 (high)
  3. Rank 3Apache Log4j

    CVE-2021-44228

    Ransomware

    Apache Log4j2 Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 10, 2021
    CISA deadline
    14 days
    CVSS severity
    10.0 (critical)
  4. Rank 4Apache Tomcat

    CVE-2025-24813

    Apache Tomcat Path Equivalence Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 1, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  5. Rank 5Apache HugeGraph

    CVE-2024-27348

    Apache HugeGraph-Server Improper Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 18, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  6. Rank 6Apache OFBiz

    CVE-2024-38856

    Apache OFBiz Incorrect Authorization Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 27, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  7. Rank 7Apache OFBiz

    CVE-2024-32113

    Apache OFBiz Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 7, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  8. Rank 8Apache Superset

    CVE-2023-27524

    Apache Superset Insecure Default Initialization of Resource Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 8, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  9. Rank 9Apache ActiveMQ

    CVE-2023-46604

    Ransomware

    Apache ActiveMQ Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 2, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  10. Rank 10Apache RocketMQ

    CVE-2023-33246

    Apache RocketMQ Command Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 6, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
Show 30 more vulnerabilities
  1. Rank 11Apache Tomcat

    CVE-2016-8735

    CVE from 2016, added in 2023

    Apache Tomcat Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 12, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  2. Rank 12Apache APISIX

    CVE-2022-24112

    Apache APISIX Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  3. Rank 13Apache CouchDB

    CVE-2022-24706

    Apache CouchDB Insecure Default Initialization of Resource Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  4. Rank 14Apache Struts

    CVE-2013-2251

    CVE from 2013, added in 2022

    Apache Struts Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  5. Rank 15Apache Tomcat

    CVE-2020-1938

    CVE from 2020, added in 2022

    Apache Tomcat Improper Privilege Management Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  6. Rank 16Apache ActiveMQ

    CVE-2016-3088

    CVE from 2016, added in 2022

    Apache ActiveMQ Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 10, 2022
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  7. Rank 17Apache Struts 1

    CVE-2017-9791

    CVE from 2017, added in 2022

    Apache Struts 1 Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 10, 2022
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  8. Rank 18Apache Struts

    CVE-2012-0391

    CVE from 2012, added in 2022

    Apache Struts 2 Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 21, 2022
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  9. Rank 19Apache Airflow

    CVE-2020-13927

    CVE from 2020, added in 2022

    Apache Airflow's Experimental API Authentication Bypass

    Added more than a year ago: ranked by severity.

    Added
    Jan 18, 2022
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  10. Rank 20Apache Shiro

    CVE-2016-4437

    CVE from 2016, added in 2021

    Apache Shiro Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  11. Rank 21Apache Struts

    CVE-2017-5638

    RansomwareCVE from 2017, added in 2021

    Apache Struts Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  12. Rank 22Apache Struts

    CVE-2020-17530

    Apache Struts Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  13. Rank 23Apache HTTP Server

    CVE-2021-41773

    Ransomware

    Apache HTTP Server Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  14. Rank 24Apache HTTP Server

    CVE-2021-42013

    Ransomware

    Apache HTTP Server Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  15. Rank 25Apache HTTP Server

    CVE-2024-38475

    Apache HTTP Server Improper Escaping of Output Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 1, 2025
    CISA deadline
    21 days
    CVSS severity
    9.1 (critical)
  16. Rank 26Apache Log4j

    CVE-2021-45046

    RansomwareCVE from 2021, added in 2023

    Apache Log4j2 Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 1, 2023
    CISA deadline
    21 days
    CVSS severity
    9.0 (critical)
  17. Rank 27Apache HTTP Server

    CVE-2021-40438

    Ransomware

    Apache HTTP Server-Side Request Forgery (SSRF)

    Added more than a year ago: ranked by severity.

    Added
    Dec 1, 2021
    CISA deadline
    14 days
    CVSS severity
    9.0 (critical)
  18. Rank 28Apache Spark

    CVE-2022-33891

    Apache Spark Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 7, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  19. Rank 29Apache Kylin

    CVE-2020-1956

    CVE from 2020, added in 2022

    Apache Kylin OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  20. Rank 30Apache Airflow

    CVE-2020-11978

    CVE from 2020, added in 2022

    Apache Airflow Command Injection

    Added more than a year ago: ranked by severity.

    Added
    Jan 18, 2022
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  21. Rank 31Apache Tomcat

    CVE-2017-12615

    RansomwareCVE from 2017, added in 2022

    Apache Tomcat on Windows Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.1 (high)
  22. Rank 32Apache Tomcat

    CVE-2017-12617

    CVE from 2017, added in 2022

    Apache Tomcat Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.1 (high)
  23. Rank 33Apache Struts

    CVE-2017-9805

    CVE from 2017, added in 2021

    Apache Struts Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.1 (high)
  24. Rank 34Apache Struts

    CVE-2018-11776

    CVE from 2018, added in 2021

    Apache Struts Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.1 (high)
  25. Rank 35Apache HTTP Server

    CVE-2019-0211

    CVE from 2019, added in 2021

    Apache HTTP Server Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  26. Rank 36Apache OFBiz

    CVE-2024-45195

    Apache OFBiz Forced Browsing Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 4, 2025
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  27. Rank 37Apache Flink

    CVE-2020-17519

    CVE from 2020, added in 2024

    Apache Flink Improper Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 23, 2024
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  28. Rank 38Apache Struts 1

    CVE-2006-1547

    CVE from 2006, added in 2022

    Apache Struts 1 ActionForm Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 21, 2022
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  29. Rank 39Apache Solr

    CVE-2019-17558

    CVE from 2019, added in 2021

    Apache Solr VelocityResponseWriter Plug-In Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  30. Rank 40Apache Solr

    CVE-2019-0193

    CVE from 2019, added in 2021

    Apache Solr DataImportHandler Code Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 10, 2021
    CISA deadline
    182 days
    CVSS severity
    7.2 (high)

Follow and verify

Get new Apache vulnerabilities: RSS feed (add it to Outlook, Teams, Slack or your feed reader).

Indicative classification, based on the vendor and product names given by CISA. How products are classified.